CVE-2026-25368

Severity
6.5MEDIUM
EPSS
0.0%
top 89.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19

Description

Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wf47-fvx4-6g8w: Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Contro2026-02-19
CVEList
WordPress Calculated Fields Form plugin <= 5.4.4.1 - Broken Access Control vulnerability2026-02-19

🕵️Threat Intelligence

1
Wiz
CVE-2026-25368 Impact, Exploitability, and Mitigation Steps | Wiz