
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24985 is a Missing Authorization (Broken Access Control) vulnerability in the WP Forms Signature Contract Add-On WordPress plugin developed by Approveme. It affects all versions up to and including 1.8.2, allowing low-privileged authenticated users (Subscriber level) to perform unauthorized actions such as dismissing admin notices. The vulnerability was reported by Nabil Irawan on December 20, 2025, and published on February 3, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has sufficient privileges before executing certain privileged actions, specifically related to notice dismissal functionality. An authenticated attacker with as little as Subscriber-level access can exploit this by sending crafted requests to the vulnerable endpoint without any authorization or nonce token check. No complex preconditions are required beyond having a valid low-privilege account on the target WordPress site. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Exploitation of this vulnerability allows a low-privileged authenticated user to perform actions restricted to higher-privileged roles, specifically dismissing administrative notices within the plugin. The confidentiality and availability impacts are none; only a low integrity impact is assessed, meaning an attacker can alter plugin state (e.g., suppress admin alerts) but cannot access sensitive data or disrupt service. The practical risk is limited, though in a broader attack chain, suppressing security notices could delay administrator awareness of other malicious activity (Patchstack).
There is no evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. No exploit kits, weaponized tools, or threat actor attribution have been identified. Patchstack classifies this as low priority with "no impactful threat," though they note vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
The vendor has released version 1.8.3 of the WP Forms Signature Contract Add-On, which patches this vulnerability. Site administrators should update the plugin to version 1.8.3 or later immediately. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, restricting Subscriber-level user registration or temporarily deactivating the plugin are viable interim mitigations (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."