Answer in brief
CVE-2026-105260 records a Unknown severity vulnerability in Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF. The current sources do not mark it as known exploited. The current feed maps Unknown/Database Addon For WPForms ( wpforms entries ) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Database Addon For WPForms ( wpforms entries ) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Database Addon For WPForms ( wpforms entries )generic | >=0 <1.1.1 | 1.1.1 |
Published upstream
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.
Quoted source text, attributed separately from HOL analysis.