Impact
The Easy Form Builder plugin for WordPress fails to verify that the value submitted in certain form types matches the configuration stored for that form, allowing unauthenticated users to submit a request that creates a new WordPress account even when the site owner has disabled public registration. This flaw permits an attacker to gain an initial authenticated session and subsequently use that account to access site content or perform privileged actions, resulting in compromise of confidentiality and integrity of site data. The weakness is an instance of improper authorization (CWE‑284).
Affected Systems
WhiteStudio’s Easy Form Builder plugin for WordPress, versions 4.0.0 through 4.1.3, are affected. All installations using these releases are vulnerable until the plugin is upgraded to 4.2.0 or later.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates moderate severity. The EPSS score of less than 1% means that, at the time of assessment, the probability of an exploitation attempt is very low, and the flaw is not listed in the CISA KEV catalog. An attacker can exploit the vulnerability remotely by submitting a crafted form request to the affected WordPress site; no user authentication or elevated privileges are required to trigger the exploit.
OpenCVE Enrichment