CVE-2026-2688
CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass
MEDIUM 6.5EPSS 0.2%
The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
- Affected
- HIPAA FORMS
- CVSS v3.1 WPSCAN
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 0.21% chance of exploitation in the next 30 days, 11th percentile
- Published
- 2026-09-02