SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-2688

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The HIPAA FORMS WordPress plugin prior to version 3.2.0 is vulnerable due to a hardcoded authentication bypass that allows unauthenticated attackers to bypass nonce validation on AJAX requests. This flaw enables unauthorized access to protected endpoints, potentially exposing sensitive data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-2688
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%
WordPress

Original NVD Description

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.