Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Edgarrojas
Edgarrojas smart Forms – When You Need More Than Just A Contact Form Wordpress Wordpress wordpress |
|
| Vendors & Products |
Edgarrojas
Edgarrojas smart Forms – When You Need More Than Just A Contact Form Wordpress Wordpress wordpress |
Sat, 14 Feb 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve donation campaign data including campaign IDs and names. | |
| Title | Smart Forms <= 2.6.99 - Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:46:27.378Z
Reserved: 2026-02-05T20:32:26.267Z
Link: CVE-2026-2022
Updated: 2026-02-17T15:36:47.783Z
Status : Deferred
Published: 2026-02-14T07:16:12.847
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-2022
No data.
OpenCVE Enrichment
Updated: 2026-04-15T20:45:06Z