AdForest <= 6.0.12 - Authentication Bypass
2026-02-11 12:46
Phat RiOStrategic Overview
StatusPatched in 6.0.13
Affected ThemeAdForest
Affected Version
<= 6.0.12CVSS9.8Critical
CVE
CVE-2026-1729Vulnerability Overview
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.
Technical Analysis
REMEDIATION: Update to version 6.0.13, or a newer patched version --- IDENTIFIER: CWE-306 (Missing Authentication for Critical Function) The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C