{"error":0,"message":null,"data":{"name":"Flamingo","plugin":"flamingo","link":"https:\/\/wordpress.org\/plugins\/flamingo\/","latest":"1787044800","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"7d05a305f3154520c9c5de510e34f004048b518b7602ccf8a21c4ab006db2eea","name":"Flamingo [flamingo] < 2.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"022a9997dfc335fe7d818f90b085eb691dd3ba3c","name":"WordPress Flamingo plugin <= 2.1 - CSV Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/flamingo\/vulnerability\/wordpress-flamingo-plugin-2-1-csv-injection-vulnerability","description":"CSV Injection vulnerability found by Vishnupriya Ilango (FortiGuard Labs) in WordPress Flamingo plugin (versions <= 2.1).","date":"2020-01-28"}],"impact":[]},{"uuid":"38ae84f27f77c068ec669d38cc0fa5aefab69c47b6e5bd5ceed189daea4518ef","name":"Flamingo [flamingo] < 2.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6f1dbe1807131bec085dd56cfbb9c0f2fe72fd1f","name":"Flamingo <= 2.1 - CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/flamingo\/flamingo-21-csv-injection","description":"A CSV Injection vulnerability was discovered in Flamingo up to version 2.1. It allows a user with low level privileges to inject OS command that will be included in the exported CSV file, leading to possible command\/code execution.","date":"2020-01-15"}],"impact":[]},{"uuid":"7dd4478708ad483c508f65fc301567e11103501c01f4f038c0906b79fd749c24","name":"Flamingo [flamingo] < 2.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"810a985f-b671-4a69-b9c3-7f35d72e84de","name":"Flamingo &lt; 2.1.1 - CSV Injection","link":"https:\/\/wpscan.com\/vulnerability\/810a985f-b671-4a69-b9c3-7f35d72e84de","description":"The Flamingo WordPress plugin was affected by a CSV Injection security vulnerability.","date":null}],"impact":[]},{"uuid":"11a8f9c12801dc4a1bfbfe6dbddf5e8bdef5dec84ba226ac744cbfbbe7cb736d","name":"Flamingo [flamingo] < 2.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12853","name":"CVE-2026-12853","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12853","description":"[en] The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate taxonomy terms including channel names derived from Contact Form 7 form titles that may reveal internal form purposes, department names, or workflow identifiers, as well as submission counts per channel and contact tag names. The plugin's flamingo_map_meta_cap() filter restricts access to Flamingo's admin UI but does not extend to WordPress core APIs such as XML-RPC wp.getTerms and admin-ajax ajax-tag-search.","date":"2026-09-07"},{"id":"8f9c63bc5f33c4f6aa6a868adccf04cc5aec843b","name":"Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/flamingo\/flamingo-262-authenticated-contributor-missing-authorization-to-unauthorized-tag-information-disclosure-via-wpgetterms-and-ajax-tag-search","description":"The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate taxonomy terms including channel names derived from Contact Form 7 form titles that may reveal internal form purposes, department names, or workflow identifiers, as well as submission counts per channel and contact tag names. The plugin's flamingo_map_meta_cap() filter restricts access to Flamingo's admin UI but does not extend to WordPress core APIs such as XML-RPC wp.getTerms and admin-ajax ajax-tag-search.","date":"2020-01-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788760045"}