The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Outlawgt
Outlawgt custom Contact Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Outlawgt
Outlawgt custom Contact Forms Wordpress Wordpress wordpress |
Sat, 05 Sep 2026 07:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-09-05T07:38:14.313Z
Updated: 2026-09-07T11:17:24.787Z
Reserved: 2026-08-17T13:16:39.258Z
Link: CVE-2026-75018
Updated: 2026-09-07T11:13:57.267Z
Status : Deferred
Published: 2026-09-05T08:16:40.397
Modified: 2026-09-08T13:12:58.310
Link: CVE-2026-75018
No data.