CVE-2026-78151 PUBLISHED

FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response

Assigner: WPScan
Reserved: 23.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.

Product Status

Vendor Unknown
Product FormLayer
Versions Default: unaffected
  • affected from 0 to 1.0.9 (excl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE