CVE-2026-85122
- EPSS 0.34%
- Veröffentlicht 18.09.2026 06:00:13
- Zuletzt bearbeitet 18.09.2026 19:08:32
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unes...
CVE-2026-85123
- EPSS 0.22%
- Veröffentlicht 18.09.2026 06:00:13
- Zuletzt bearbeitet 18.09.2026 19:08:32
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has...
CVE-2026-13439
- EPSS 0.4%
- Veröffentlicht 21.07.2026 05:35:29
- Zuletzt bearbeitet 21.07.2026 16:54:45
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session ide...
CVE-2024-30535
- EPSS 0.49%
- Veröffentlicht 31.03.2024 19:15:46
- Zuletzt bearbeitet 28.04.2026 19:24:09
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4.
CVE-2022-3906
- EPSS 0.39%
- Veröffentlicht 12.12.2022 18:15:11
- Zuletzt bearbeitet 22.04.2025 21:15:43
The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis...