VYPR

FormLayer

by WordPress

CVEs (2)

  • CVE-2026-78151MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation…

  • CVE-2026-59519MedJul 5, 2026
    risk 0.00cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.