A vulnerability has been found in Advanced Form Integration Plugin up to 2.6.0 on WordPress and classified as critical. This impacts the function
admin_init of the file /wp-admin/profile.php. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-16587. It is possible to initiate the attack remotely. There is no exploit available.