Constant Contact Forms <= 2.22.0 - Improper Authentication to Unauthenticated Mailing List Subscription of Arbitrary Users via Login Opt-in

Medium 5.3 CWE-287Fixed in 2.22.1
ID
WPSEC-2026-0670
Plugin
Constant Contact Forms (constant-contact-forms)
Affected
all versions before 2.22.1
Remediation
Update to 2.22.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-287
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Constant Contact Forms on WPSec AttackSurface
Fix released
Published

Description

The Constant Contact Forms plugin for WordPress is vulnerable to Improper Authentication in all versions up to, and including, 2.22.0. The login opt-in handler ran before WordPress verified the submitted password, did not check whether the login opt-in was enabled, and identified the account by the submitted username alone. This makes it possible for unauthenticated attackers who know a username to subscribe that user's email address to the site's Constant Contact mailing lists without the user's consent.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0