PT-2026-95238 · Whitestudio · Easy Form Builder
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easy Form Builder by WhiteStudio versions prior to 4.2.0
Description
Lack of validation for submitted values against stored configurations in certain form types allows unauthenticated users to store arbitrary content. This content is subsequently rendered without escaping on an administrative page, resulting in Stored XSS (Cross-Site Scripting), a technique where malicious scripts are permanently stored on the target server and executed in the browser of an authenticated administrator.
Recommendations
Update Easy Form Builder by WhiteStudio to version 4.2.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Form Builder