Security Advisory

CVE-2026-2688

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-02 14:16:47
Last updated 2026-09-02 14:57:38
Assigner WPScan
CVSS score 6.5
State PUBLISHED

Description

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.