Easy Form Builder [easy-form-builder-by-bitware] <= 1.0 (unfixed + closed)
unknown
[en] The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 12, 2021
CVE-2021-24224 on NVD →
Easy Form Builder [easy-form-builder-by-bitware] <= 1.0 (unfixed + closed)
unknown
Unauthorized AJAX Calls vulnerability discovered by WPScan Team in WordPress Easy Form Builder plugin (versions <= 1.0).
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 27, 2021
Easy Form Builder <= 1.0 - Arbitrary File Upload
high
The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.
- CVSS:
- 8.8
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 26, 2021
CVE-2021-24224 on NVD →
Easy Form Builder [easy-form-builder-by-bitware] <= 1.0 (unfixed + closed)
unknown
While confirming https://wpscan.com/vulnerability/ed0c054b-54bf-4df8-9015-c76704c93484, we noticed that all AJAX actions of the plugin, available to authenticated users, do not have any CSRF and authorisation checks in place, allowing low privilege users to call them and delete/edit arbitrary forms and their data for e...
- Affected:
- up to 1.0
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database