Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-11794 – Unauthenticated Privilege Escalation – Advanced Form Integration WordPress Plugi…

Be the first to know when new zero-days emerge:

Summary

CVE-2026-11794 is a high-severity unauthenticated privilege escalation vulnerability in the Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin, affecting all versions prior to 2.1.1. The flaw allows unauthenticated remote attackers to create WordPress administrator accounts by submitting manipulated role values through public-facing forms, resulting in complete site takeover. It carries a CVSS v3.1 score of 8.1 (HIGH).

Technical details

  • Root cause: The plugin fails to enforce server-side restrictions on the WordPress role field when creating user accounts from form submissions (CWE-269: Improper Privilege Management). The vulnerability is present in the WooCommerce Create Customer and FluentAffiliate Create Affiliate integration actions, where the role value is accepted directly from attacker-controlled form input without validation.
  • Trigger conditions: Exploitation requires an active integration in which the site administrator has mapped the WordPress user role field to a public, attacker-controllable form input — a non-default configuration. Additional prerequisites include having WooCommerce or FluentAffiliate active alongside a Breakdance page builder form configured with such an integration.
  • Attack vector: An unauthenticated attacker submits a crafted HTTP POST request to wp-admin/admin-ajax.php using the breakdance_form_custom action, supplying administrator as the role field value. Because no server-side check validates or restricts the submitted role, the plugin creates a fully privileged WordPress administrator account on behalf of the attacker.
  • Impact: Successful exploitation grants the attacker complete WordPress administrative access, enabling arbitrary plugin or theme installation, backdoor injection, remote code execution, and full site takeover.

Affected software

  • Advanced Form Integration — Connect Forms to 200+ Apps: all versions prior to 2.1.1

Severity

  • CVSS v3.1 Base Score: 8.1 (HIGH)
  • Vector string: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Mitigation and recommended actions

  • Immediate: Update the plugin to version 2.1.1 or later. Version 2.1.1 introduces server-side role validation that explicitly blocks the assignment of privileged roles — including administrator, editor, author, and shop_manager — via form submissions, and adds security logging for any blocked role assignment attempts.
  • If immediate update is not possible: Disable or remove any active integrations that map the WordPress user role field to a public-facing form input until the plugin can be updated to version 2.1.1 or later.

IONIX Status

The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge