PT-2026-8046 · WordPress · Easy Form Builder

·

CVE-2025-14067

·

Publicado

2026-02-14

·

Atualizado

2026-02-14

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easy Form Builder plugin for WordPress versions through 3.9.3
Description The Easy Form Builder plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on multiple AJAX actions. Attackers with Subscriber-level access or higher can retrieve sensitive form response data, including messages, admin replies, and user information. The issue stems from a logic error in the authorization check, where the AND operator (&&) was used instead of the OR operator (||). The vulnerable AJAX actions allow retrieval of data without proper authorization.
Recommendations Update the Easy Form Builder plugin to a version later than 3.9.3.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14067

Produtos afetados

Easy Form Builder