WordPress security changelog
CRITICAL CVE-2026-13439 Deferred

Easy Form Builder by WhiteStudio – Drag & Drop Form Builder: Privilege escalation or authentication bypass

Easy Form Builder by WhiteStudio – Drag & Drop Form Builder is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 4.0.11.

CVE / CNA score 9.8 CVSS 3.1 · security@wordfence.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder
Plugin slug
easy-form-builder
Affected
<= 4.0.11
Safe version
> 4.0.11
Published
Jul 21, 2026
Weakness
CWE-269 — Improper Privilege Management

This CVE was published Jul 21, 2026 and is one of 9 known issues for this plugin.

Patch or disable the affected component.

Update Easy Form Builder by WhiteStudio – Drag & Drop Form Builder to a release after 4.0.11, or disable and remove it until a fixed version is available.

Technical description

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via Emsfb/v1/forms/message/add, and then calling Emsfb/v1/forms/recovery/efb_set_password with the known sid to set an arbitrary new password and gain full administrator access.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Primary and upstream sources