PoC Index82,564 CVEs with PoCs

CVE-2026-2688

CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass

MEDIUM 6.5EPSS 0.2%

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.

Affected
HIPAA FORMS
CVSS v3.1 WPSCAN
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.21% chance of exploitation in the next 30 days, 11th percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References