Security Advisory

CVE-2026-2688

6.5
MEDIUM

Vulnerability Description

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
Published Date September 2, 2026
Official Source NIST NVD Advisory