CVE-2026-12400 is an insecure direct object reference vulnerability in the FlowForms – Conversational Form Builder plugin for WordPress affecting all versions through 1.1.1. The flaw exists in the update_form functionality, where the application fails to properly validate a user-controlled form identifier supplied through the REST URL. Because object-level authorization is not correctly enforced, an authenticated user with contributor-level privileges or higher can target arbitrary form records rather than being restricted to forms they are authorized to manage. Successful exploitation allows unauthorized modification of form content, design, and settings, and also permits publishing or reverting forms, including forms owned by administrators.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-12400 affecting the FlowForms WordPress plugin up to 1.1.1. Repository structure is minimal: README.md documents the vulnerability and attack flow, exploit.py contains the full exploit logic and UI, and requirements.txt lists dependencies (requests, rich, urllib3). The exploit is not part of a larger framework. The exploit's purpose is authenticated arbitrary modification of FlowForms forms via an IDOR in two REST API routes. Based on the README and visible code, the workflow is: authenticate to WordPress with supplied low-privileged credentials, obtain a REST nonce from the admin interface, enumerate candidate form IDs by checking /flowform/{id}, and then submit crafted JSON to vulnerable FlowForms REST endpoints. It supports three modes: name (rename a form), content (replace form screens/layout/background/redirect), and email (rewrite notification settings so future submissions are delivered to an attacker mailbox). The code is operational rather than a mere proof-of-concept because it includes hardcoded payloads and a complete CLI flow with arguments for target URL, proxy, form ID range, credentials, and exploit mode. The visible payloads show concrete malicious outcomes: defacement text, attacker-themed imagery, redirect manipulation, and notification hijacking to phantom@hat.com. No shell execution or host-level code execution is present; this is an application-layer abuse exploit targeting authorization flaws in a web plugin.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.