PT-2026-95239 · Whitestudio · Easy Form Builder
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Form Builder by WhiteStudio versions prior to 4.2.0
Description
Certain form types in the plugin fail to validate submitted values against the stored configuration. This flaw allows unauthenticated users to bypass registration policies and create WordPress accounts on sites where registration has been disabled by the owner.
Recommendations
Update Easy Form Builder by WhiteStudio to version 4.2.0 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Form Builder