CVE-2026-11562
MEDIUMWS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-11562. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-11562, a missing capability check in the WS Form LITE WordPress plugin (before 1.11.8). The code includes placeholder logic for network probing but lacks actual exploit implementation for modifying plugin settings.
Description
The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-11562, a missing capability check in the WS Form LITE WordPress plugin (before 1.11.8). The code includes placeholder logic for network probing but lacks actual exploit implementation for modifying plugin settings.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N