Impact
The vulnerability arises because the Easy Form Builder plugin fails to validate submitted values against its stored configuration for a subset of form types, enabling attackers to store malicious content that is later rendered unescaped on an admin page. This permits the execution of arbitrary JavaScript in the context of administrators, potentially leading to session hijacking, security cookie theft, defacement, or the installation of malicious extensions.
Affected Systems
WordPress sites using the WhiteStudio Easy Form Builder plugin versions 4.0.0 through 4.1.3 are affected. Any installation that has not been upgraded to 4.2.0 or newer carries this risk.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is classified as high severity, and while the EPSS score of less than 1% indicates a low to moderate probability of exploitation in the current window, the fact that the flaw is exploitable by unauthenticated users through standard form submissions means it can be weaponized at low effort. The vulnerability is not listed in CISA’s KEV catalog, but the impact on an exposed admin interface makes it a high‑risk issue that should be addressed promptly.
OpenCVE Enrichment