CVE-2026-11794

HIGH

Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-11794. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-11794, a WordPress plugin vulnerability allowing unauthorized user role assignment via public form submissions. The code includes placeholder methods (`check()` and `run()`) but lacks actual exploit implementation or technical details about the vulnerability mechanics.

Description

The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-11794_the_advanced_form.py

This repository contains an auto-generated stub module for CVE-2026-11794, a WordPress plugin vulnerability allowing unauthorized user role assignment via public form submissions. The code includes placeholder methods (`check()` and `run()`) but lacks actual exploit implementation or technical details about the vulnerability mechanics.

Classification
Stub 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1
No auth needed
Prerequisites: Target must have the vulnerable WordPress plugin installed (<2.1.1) · Public form submission functionality must be enabled
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/614b9517-d6d5-499f-8172-280280a312b2/

Scores

CVSS v3 8.1
EPSS 0.0024
EPSS Percentile 14.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

Status published
Products (1)
None/Advanced Form Integration — Connect Forms to 200+ Apps < 2.1.1
Published Jul 01, 2026
Tracked Since Jul 01, 2026