Security Advisory
CVE-2026-2688
6.5
MEDIUM
Vulnerability Description
The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
Published Date
September 2, 2026
Official Source
NIST NVD Advisory