← Database

CVE-2026-2688

MEDIUM CVSS: 6.5 Published: 2026-09-02 Modified: 2026-09-02

Description

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.

Affected Platforms

Unknown

Weakness Type

CWE-863

References