Vulnerabilities / Constant Contact Forms / WPSEC-2026-0670
Constant Contact Forms <= 2.22.0 - Improper Authentication to Unauthenticated Mailing List Subscription of Arbitrary Users via Login Opt-in
Medium 5.3
CWE-287Fixed in 2.22.1
- ID
- WPSEC-2026-0670
- Plugin
- Constant Contact Forms (constant-contact-forms)
- Affected
- all versions before 2.22.1
- Remediation
- Update to 2.22.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-287
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Constant Contact Forms on WPSec AttackSurface
- Fix released
- Published
Description
The Constant Contact Forms plugin for WordPress is vulnerable to Improper Authentication in all versions up to, and including, 2.22.0. The login opt-in handler ran before WordPress verified the submitted password, did not check whether the login opt-in was enabled, and identified the account by the submitted username alone. This makes it possible for unauthenticated attackers who know a username to subscribe that user's email address to the site's Constant Contact mailing lists without the user's consent.
References
- https://wpsec.com/vuln/WPSEC-2026-0670/
- https://plugins.svn.wordpress.org/constant-contact-forms/tags/2.22.1/
- https://wordpress.org/plugins/constant-contact-forms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS