Unrated severityNVD Advisory· Published Jul 1, 2026· Updated Jul 1, 2026
WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
CVE-2026-11562
Description
The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.
Affected products
1- Range: <1.11.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/e0283d75-0622-490c-9442-cf1aa0a1d167/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.