CVE-2026-2470
The Pagelayer plugin for WordPress has a security flaw that allows attackers with contributor-level access and above to set up custom contact form templates that can be used by anyone to send emails, even if they're not logged in. This is because the plugin doesn't properly check who can access and edit these templates, and the templates can be triggered by anyone through a special URL parameter. The vulnerability can be exploited by chaining it with another known issue to gain even more control over email behavior.
Based on public CVE data (MITRE/NVD).