CVE-2026-5229Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common), the plugin falls back to reading the 'form_notify_line_email' cookie value without verifying that the LINE account is associated with that email address. This makes it possible for unauthenticated attackers to gain access to any user account on the site, including administrator accounts, by completing a LINE OAuth flow with their own LINE account while injecting a malicious cookie containing the target victim's email address.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-15: 3Patch / Workaround · 2026-05-15: 2Technical Details · 2026-05-15: 305-15
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Form Notify WordPress Plugin Authentication Bypass (CVE-2026-5229) The Form Notify plugin for WordPress (up to and including 1.1.10) is vulnerable to Authentication Bypass. It trusts user-controlled cookie data (form_notify_line_email) during LINE OAuth login without proper verification. When LINE does not provide an email (common behavior), unauthenticated attackers can inject a malicious cookie and gain access to any user account on the site, including administrators. 👉Affected: Form Notify <= 1.1.10

    Post summary

    The post announces a new authentication bypass vulnerability (CVE-2026‑5229) in Form Notify WordPress plugin, explaining how unauthenticated attackers can exploit cookie handling during LINE OAuth to gain administrative access.

    00011103
    196 followersView on X
  • AI Heartland@peaks2314
    Disclosure

    🚨 WordPress Form Notify プラグイン 認証バイパス(CVSS 9.8) ▼何が起きた LINE OAuthログイン後、未認証の攻撃者が細工したCookieで任意のWordPressアカウント(管理者含む)に不正ログインできる脆弱性(CVE-2026-5229)が公表された。 ▼影響 Form Notify 1.1.10 以下を使用するWordPressサイト。 ▼対応 プラグインを最新バージョンへ即時更新、または一時無効化。 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-5229 #WordPress

    Post summary

    A high‑severity authentication bypass (CVE‑2026‑5229) was disclosed for WordPress Form Notify ≤1.1.10, allowing attackers to log in as any user via a crafted cookie after OAuth login, with an immediate update or disable advised.

    00010146
    3.0K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5229 — CVSS 9.8/10 ██████████ The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10.... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/v31PGhh1YV

    Post summary

    The tweet announces CVE-2026-5229, a critical authentication bypass in the Form Notify WordPress plugin, and notes that a patch is available.

    1000095
    42 followersView on X

Explore more