CVE-2026-4281Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the connect() and listen_for_tokens() methods of the FormLift_Infusionsoft_Manager class, both of which are hooked to 'plugins_loaded' and execute on every page load. The connect() function generates an OAuth connection password and leaks it in the redirect Location header without verifying the requesting user is authenticated or authorized. The listen_for_tokens() function only validates the temporary password but performs no user authentication before calling update_option() to save attacker-controlled OAuth tokens and app domain. This makes it possible for unauthenticated attackers to hijack the site's Infusionsoft connection by first triggering the OAuth flow to obtain the temporary password, then using that password to set arbitrary OAuth tokens and app domain via update_option(), effectively redirecting the plugin's API communication to an attacker-controlled server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 203-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Patch

    Unauthenticated users can hijack Infusionsoft connections via FormLift Web Forms due to missing authorization (CVE-2026-4281). This vulnerability could lead to data breaches. Update to version 7.5.22 immediately to secure your systems. #CyberSecurity #InfoSec https://t.co/R8s5IKykoc

    Post summary

    The tweet announces CVE-2026-4281, a missing‑authorization flaw that allows unauthenticated users to hijack Infusionsoft connections through FormLift Web Forms, and urges an immediate upgrade to version 7.5.22 to mitigate the risk.

    0000036
    50 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4281 The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing… https://www.cve.org/CVERecord?id=CVE-2026-4281

    Post summary

    The post discloses that FormLift for Infusionsoft Web Forms plugin up to version 7.5.21 suffers from a missing authorization vulnerability, without providing PoC, exploit code, or patch details.

    00000106
    56.8K followersView on X

Explore more