
🚨Critical - Form Notify WordPress Plugin Authentication Bypass (CVE-2026-5229) The Form Notify plugin for WordPress (up to and including 1.1.10) is vulnerable to Authentication Bypass. It trusts user-controlled cookie data (form_notify_line_email) during LINE OAuth login without proper verification. When LINE does not provide an email (common behavior), unauthenticated attackers can inject a malicious cookie and gain access to any user account on the site, including administrators. 👉Affected: Form Notify <= 1.1.10
Post summary
The post announces a new authentication bypass vulnerability (CVE-2026‑5229) in Form Notify WordPress plugin, explaining how unauthenticated attackers can exploit cookie handling during LINE OAuth to gain administrative access.


