Easy Form Builder by WhiteStudio – Drag & Drop Form Builder: Privilege escalation or authentication bypass
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 4.0.11.
- Component
- Easy Form Builder by WhiteStudio – Drag & Drop Form Builder
- Plugin slug
easy-form-builder- Affected
- <= 4.0.11
- Safe version
> 4.0.11- Published
- Jul 21, 2026
This CVE was published Jul 21, 2026 and is one of 9 known issues for this plugin.
Patch or disable the affected component.
Update Easy Form Builder by WhiteStudio – Drag & Drop Form Builder to a release after 4.0.11, or disable and remove it until a fixed version is available.
Technical description
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via Emsfb/v1/forms/message/add, and then calling Emsfb/v1/forms/recovery/efb_set_password with the known sid to set an arbitrary new password and gain full administrator access.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Primary and upstream sources
- NVD record for CVE-2026-13439
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- Wordfence advisory wordfence.com