Description
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Upgrade
AI Analysis

Impact

The vulnerability arises because the Easy Form Builder plugin fails to validate submitted values against its stored configuration for a subset of form types, enabling attackers to store malicious content that is later rendered unescaped on an admin page. This permits the execution of arbitrary JavaScript in the context of administrators, potentially leading to session hijacking, security cookie theft, defacement, or the installation of malicious extensions.

Affected Systems

WordPress sites using the WhiteStudio Easy Form Builder plugin versions 4.0.0 through 4.1.3 are affected. Any installation that has not been upgraded to 4.2.0 or newer carries this risk.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is classified as high severity, and while the EPSS score of less than 1% indicates a low to moderate probability of exploitation in the current window, the fact that the flaw is exploitable by unauthenticated users through standard form submissions means it can be weaponized at low effort. The vulnerability is not listed in CISA’s KEV catalog, but the impact on an exposed admin interface makes it a high‑risk issue that should be addressed promptly.

Generated by OpenCVE AI on September 19, 2026 at 19:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Easy Form Builder plugin to version 4.2.0 or later.
  • If an immediate upgrade is not possible, disable the vulnerable form types or remove the plugin entirely until the patch is applied.
  • Consider implementing a web application firewall rule that blocks script payloads sent to the form submission endpoint to mitigate the risk until remediation occurs.

Generated by OpenCVE AI on September 19, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions easy Form Builder
Vendors & Products Wordpress-extensions
Wordpress-extensions easy Form Builder

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
Title Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion
References

Subscriptions

Wordpress-extensions Easy Form Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:11:54.980Z

Reserved: 2026-09-03T08:02:51.827Z

Link: CVE-2026-85122

cve-icon Vulnrichment

Updated: 2026-09-18T11:04:17.662Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:39.880

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-85122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')