plugin

E Shot Form Builder Vulnerabilities

2 known security issues reported for the E Shot Form Builder WordPress plugin. Most recent disclosed Apr 14, 2026.

2 medium

Running E Shot Form Builder on your site? Check whether your installed version is affected.

Scan your site free

e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX

medium

The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). The function is registe...

CVSS:
5.3
Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Apr 14, 2026

CVE-2026-3642 on NVD →

e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action

medium

The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The function lacks any capability check (e.g., curr...

CVSS:
5.3
Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Mar 20, 2026

CVE-2026-3546 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database