plugin

Easy Form Builder Vulnerabilities

17 known security issues reported for the Easy Form Builder WordPress plugin. Most recent disclosed Jul 21, 2026.

2 critical 3 high 5 medium

Running Easy Form Builder on your site? Check whether your installed version is affected.

Scan your site free

Easy Form Builder by WhiteStudio – Drag & Drop Form Builder <= 4.0.12 - Unauthenticated Stored Cross-Site Scripting

high

The Easy Form Builder by WhiteStudio – Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
7.2
Affected:
up to 4.0.12
Fixed in:
4.0.13
Disclosed:
Jul 21, 2026

CVE-2026-59517 on NVD →

Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint

critical

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_li...

CVSS:
9.8
Affected:
up to 4.0.11
Fixed in:
4.0.12
Disclosed:
Jul 20, 2026

CVE-2026-13439 on NVD →

Easy Form Builder by WhiteStudio — Drag & Drop Form Builder <= 4.0.6 - Unauthenticated SQL Injection

high

The Easy Form Builder by WhiteStudio — Drag & Drop Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

CVSS:
7.5
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
May 28, 2026

CVE-2026-42747 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] < 3.9.4

unknown

[en] The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form resp...

Affected:
up to 3.9.4
Fixed in:
3.9.4
Disclosed:
Feb 14, 2026

CVE-2025-14067 on NVD →

Easy Form Builder <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Response Data Exposure

medium

The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form response...

CVSS:
5.3
Affected:
up to 3.9.3
Fixed in:
3.9.4
Disclosed:
Feb 13, 2026

CVE-2025-14067 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] <= 3.9.6 (unfixed)

unknown

[en] Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.9.6.

Affected:
up to 3.9.6
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2026-22472 on NVD →

Easy Form Builder <= 3.9.6 - Missing Authorization

medium

The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.9.6
Fixed in:
4.0.0
Disclosed:
Jan 6, 2026

CVE-2026-22472 on NVD →

Easy Form Builder <= 3.8.20 - Missing Authorization

medium

The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.20. This makes it possible for unauthenticated attac...

CVSS:
5.3
Affected:
up to 3.8.20
Fixed in:
3.8.21
Disclosed:
Dec 15, 2025

CVE-2025-67577 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] <= 3.8.20 (unfixed)

unknown

[en] Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20.

Affected:
up to 3.8.20
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67577 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] < 3.8.16

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder allows Blind SQL Injection. This issue affects Easy Form Builder: from n/a through 3.8.15.

Affected:
up to 3.8.16
Fixed in:
3.8.16
Disclosed:
Aug 14, 2025

CVE-2025-54678 on NVD →

Easy Form Builder <= 3.8.15 - Unauthenticated SQL Injection

high

The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...

CVSS:
7.5
Affected:
up to 3.8.15
Fixed in:
3.8.16
Disclosed:
Aug 7, 2025

CVE-2025-54678 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] < 3.8.9

unknown

[en] The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient inpu...

Affected:
up to 3.8.9
Fixed in:
3.8.9
Disclosed:
Jan 8, 2025

CVE-2024-12112 on NVD →

Easy Form Builder <= 3.8.8 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input san...

CVSS:
6.4
Affected:
up to 3.8.8
Fixed in:
3.8.9
Disclosed:
Jan 7, 2025

CVE-2024-12112 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] < 3.7.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4.

Affected:
up to 3.7.5
Fixed in:
3.7.5
Disclosed:
Mar 31, 2024

CVE-2024-30535 on NVD →

Easy Form Builder <= 3.7.4 - Authenticated (Contributor+) SQL Injection

critical

The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access a...

CVSS:
9.9
Affected:
up to 3.7.4
Fixed in:
3.7.5
Disclosed:
Mar 29, 2024

CVE-2024-30535 on NVD →

Easy Form Builder by WhiteStudio — Drag &amp; Drop Form Builder [easy-form-builder] < 3.4.0

unknown

[en] The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
Dec 12, 2022

CVE-2022-3906 on NVD →

Easy Form Builder <= 3.3.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Easy Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...

CVSS:
5.5
Affected:
up to 3.3.8
Fixed in:
3.4.0
Disclosed:
Nov 16, 2022

CVE-2022-3906 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database