A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-5229

CVE-2026-5229: Form Notify Auth Bypass Vulnerability

CVE-2026-5229 is an authentication bypass flaw in the Form Notify WordPress plugin that allows attackers to gain unauthorized access to any user account by exploiting LINE OAuth login cookie validation. Learn its impact.

Published: May 21, 2026

CVE-2026-5229 Overview

CVE-2026-5229 is an authentication bypass vulnerability in the Form Notify plugin for WordPress, affecting versions up to and including 1.1.10. The plugin trusts user-controlled cookie data when determining which WordPress account to authenticate after a LINE OAuth login. When LINE does not return an email address, the plugin falls back to reading the form_notify_line_email cookie without verifying that the LINE account is associated with that email. Unauthenticated attackers can complete a LINE OAuth flow with their own LINE account while injecting a cookie containing a victim's email address, gaining access to that user's WordPress account, including administrator accounts. The flaw is classified under [CWE-287] Improper Authentication.

Critical Impact

Unauthenticated attackers can take over any WordPress account, including administrators, by injecting a cookie during the LINE OAuth flow.

Affected Products

  • Form Notify plugin for WordPress, versions up to and including 1.1.10
  • Fixed in Form Notify version 1.1.10 (cookie fallback removal) with additional hardening in 1.1.11
  • WordPress sites configured with LINE Login via the Form Notify plugin

Discovery Timeline

  • 2026-05-15 - CVE CVE-2026-5229 published to NVD
  • 2026-05-15 - Last updated in NVD database

Technical Details for CVE-2026-5229

Vulnerability Analysis

The vulnerability resides in the LINE OAuth login flow implemented in src/APIs/Line/Login/Route.php and src/APIs/Line/Login/User.php. After a successful LINE OAuth callback, the plugin attempts to associate the LINE identity with a WordPress account using an email address. LINE OAuth frequently omits the email field from the userinfo response. In that case, the plugin reads the form_notify_line_email cookie set on the client and uses its value as the lookup key for get_user_by('email', ...). No cryptographic binding exists between the LINE account presented and the email value read from the cookie.

An attacker initiates the LINE OAuth flow from their own browser using their own LINE account. Before the callback is processed, the attacker overwrites the form_notify_line_email cookie with the email of any registered WordPress user, including an administrator. The plugin then logs the attacker into the victim's account, granting full session privileges. Exploitation is unauthenticated, requires no user interaction beyond the attacker's own OAuth flow, and is reachable over the network.

Root Cause

The root cause is trust placed in client-controlled state to drive an authentication decision. The plugin treats a cookie value as an authoritative identifier instead of binding the WordPress account to a verified LINE user ID returned by the identity provider.

Attack Vector

The attack is remote and pre-authentication. The attacker only needs a valid LINE account, the target site's LINE login URL, and the email address of the victim account.

php
// Patch reference: form-notify.php version bump removing cookie-based email fallback
 * Plugin Name:       FormNotify
 * Plugin URI:        https://oberonlai.blog/form-notify
 * Description:       Notification for WordPress form plugins.
- * Version:           1.1.09
+ * Version:           1.1.10
 * Author:            Daily WPdev.

Source: GitHub commit 5eab0ea. The accompanying code change removes the form_notify_line_email cookie fallback in src/APIs/Line/Login/User.php around lines 53 and 72, and the route handler in src/APIs/Line/Login/Route.php lines 116-118.

Detection Methods for CVE-2026-5229

Indicators of Compromise

  • Unexpected administrator or privileged user logins originating from the LINE OAuth callback endpoint registered by the Form Notify plugin.
  • HTTP requests to the LINE login callback that include a form_notify_line_email cookie whose value does not match the email returned by the LINE userinfo response.
  • Newly issued WordPress session cookies for administrator accounts immediately following a /wp-json/ or LINE OAuth callback request from an unfamiliar IP address.

Detection Strategies

  • Inspect web server access logs for requests to the Form Notify LINE login callback and correlate them with wp_login events for high-privilege users.
  • Audit installed Form Notify plugin versions across managed WordPress sites and flag any instance running version 1.1.10 or earlier.
  • Enable WordPress authentication logging plugins or SIEM ingestion of wp_login and wp_login_failed actions to identify anomalous login patterns tied to LINE OAuth.

Monitoring Recommendations

  • Forward WordPress authentication and plugin update logs to a centralized SIEM and alert on administrator logins via the LINE OAuth handler.
  • Monitor for cookie tampering by recording Cookie headers on the LINE callback endpoint and alerting when form_notify_line_email is present alongside an authenticated session change.
  • Track outbound HTTP traffic from the WordPress host to LINE OAuth endpoints to baseline normal activity and surface anomalies.

How to Mitigate CVE-2026-5229

Immediate Actions Required

  • Update the Form Notify plugin to version 1.1.11 or later on every WordPress site where it is installed.
  • Force a password reset and invalidate active sessions for all administrator and privileged accounts on affected sites.
  • Review user lists for unauthorized accounts and audit recent administrative changes, including new plugins, themes, and option modifications.

Patch Information

The vendor released version 1.1.10, which removes the cookie-based email fallback in the LINE login flow, and version 1.1.11, which adds broader security hardening. Reference commits: GitHub commit 5eab0ea and GitHub commit 9780764. Additional details are available in the Wordfence Vulnerability Report and the WordPress Plugin Changeset.

Workarounds

  • Deactivate the Form Notify plugin until the site can be upgraded to a fixed version.
  • Disable the LINE Login feature within the plugin configuration if deactivation is not possible.
  • Use a web application firewall rule to strip or block the form_notify_line_email cookie on requests to the LINE OAuth callback endpoint.
bash
# Update the Form Notify plugin via WP-CLI to the patched release
wp plugin update form-notify --version=1.1.11
wp plugin list --name=form-notify --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechWordpress

  • SeverityCRITICAL

  • CVSS Score9.8

  • EPSS Probability0.42%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-287
  • Technical References
  • GitHub Commit Change

  • GitHub Commit Change

  • WordPress Plugin Code Review

  • WordPress Plugin Code Review

  • WordPress Plugin Code Review

  • WordPress Plugin Code Review

  • WordPress Plugin Code Review

  • WordPress Plugin Code Review

  • WordPress Plugin Changeset

  • Wordfence Vulnerability Report
  • Related CVEs
  • CVE-2025-15369: Xpro Addons Auth Bypass Vulnerability

  • CVE-2026-8610: WordPress TypeSquare Plugin Auth Bypass

  • CVE-2026-8681: WordPress Essential Chat Support Bypass

  • CVE-2025-4202: Multicollab WordPress Auth Bypass Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English