Easy Form Builder by WhiteStudio – Drag & Drop Form Builder <= 4.0.12 - Unauthenticated Stored Cross-Site Scripting
high
The Easy Form Builder by WhiteStudio – Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 7.2
- Affected:
- up to 4.0.12
- Fixed in:
- 4.0.13
- Disclosed:
- Jul 21, 2026
CVE-2026-59517 on NVD →
Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint
critical
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_li...
- CVSS:
- 9.8
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.12
- Disclosed:
- Jul 20, 2026
CVE-2026-13439 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder <= 4.0.6 - Unauthenticated SQL Injection
high
The Easy Form Builder by WhiteStudio — Drag & Drop Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...
- CVSS:
- 7.5
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.7
- Disclosed:
- May 28, 2026
CVE-2026-42747 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] < 3.9.4
unknown
[en] The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form resp...
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Feb 14, 2026
CVE-2025-14067 on NVD →
Easy Form Builder <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Response Data Exposure
medium
The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form response...
- CVSS:
- 5.3
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.4
- Disclosed:
- Feb 13, 2026
CVE-2025-14067 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] <= 3.9.6 (unfixed)
unknown
[en] Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.9.6.
- Affected:
- up to 3.9.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2026-22472 on NVD →
Easy Form Builder <= 3.9.6 - Missing Authorization
medium
The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.9.6
- Fixed in:
- 4.0.0
- Disclosed:
- Jan 6, 2026
CVE-2026-22472 on NVD →
Easy Form Builder <= 3.8.20 - Missing Authorization
medium
The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.20. This makes it possible for unauthenticated attac...
- CVSS:
- 5.3
- Affected:
- up to 3.8.20
- Fixed in:
- 3.8.21
- Disclosed:
- Dec 15, 2025
CVE-2025-67577 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] <= 3.8.20 (unfixed)
unknown
[en] Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20.
- Affected:
- up to 3.8.20
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67577 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] < 3.8.16
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder allows Blind SQL Injection. This issue affects Easy Form Builder: from n/a through 3.8.15.
- Affected:
- up to 3.8.16
- Fixed in:
- 3.8.16
- Disclosed:
- Aug 14, 2025
CVE-2025-54678 on NVD →
Easy Form Builder <= 3.8.15 - Unauthenticated SQL Injection
high
The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL quer...
- CVSS:
- 7.5
- Affected:
- up to 3.8.15
- Fixed in:
- 3.8.16
- Disclosed:
- Aug 7, 2025
CVE-2025-54678 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] < 3.8.9
unknown
[en] The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient inpu...
- Affected:
- up to 3.8.9
- Fixed in:
- 3.8.9
- Disclosed:
- Jan 8, 2025
CVE-2024-12112 on NVD →
Easy Form Builder <= 3.8.8 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input san...
- CVSS:
- 6.4
- Affected:
- up to 3.8.8
- Fixed in:
- 3.8.9
- Disclosed:
- Jan 7, 2025
CVE-2024-12112 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] < 3.7.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4.
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.5
- Disclosed:
- Mar 31, 2024
CVE-2024-30535 on NVD →
Easy Form Builder <= 3.7.4 - Authenticated (Contributor+) SQL Injection
critical
The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access a...
- CVSS:
- 9.9
- Affected:
- up to 3.7.4
- Fixed in:
- 3.7.5
- Disclosed:
- Mar 29, 2024
CVE-2024-30535 on NVD →
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder [easy-form-builder] < 3.4.0
unknown
[en] The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
- Disclosed:
- Dec 12, 2022
CVE-2022-3906 on NVD →
Easy Form Builder <= 3.3.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Easy Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...
- CVSS:
- 5.5
- Affected:
- up to 3.3.8
- Fixed in:
- 3.4.0
- Disclosed:
- Nov 16, 2022
CVE-2022-3906 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database