CVE-2026-1753

MEDIUM

Gutena Forms <1.6.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

Scores

CVSS v3 6.8
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Published Mar 11, 2026
Tracked Since Mar 11, 2026