No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Fri, 18 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration. | |
| Title | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type Confusion | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-18T11:11:39.980Z
Reserved: 2026-09-03T08:02:54.120Z
Link: CVE-2026-85123
Updated: 2026-09-18T11:04:02.661Z
Status : Received
Published: 2026-09-18T06:16:39.990
Modified: 2026-09-18T12:17:26.850
Link: CVE-2026-85123
No data.
OpenCVE Enrichment
No data.
-
CWE-284
Improper Access Control