PT-2026-61826 · Whitestudio · Easy Form Builder
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easy Form Builder by WhiteStudio versions prior to 4.0.12
Description
An unauthenticated privilege escalation allows attackers to gain administrator access. The issue stems from the password recovery flow using a publicly-visible session identifier
sid as the password reset token stored in wp emsfb temp links. This is combined with a publicly-accessible nonce refresh endpoint 'Emsfb/v1/nonce/refresh' that provides valid WordPress REST nonces to unauthenticated visitors. An attacker can scrape the sid from a published login form page, submit a recovery request for a known user email via the 'Emsfb/v1/forms/message/add' endpoint, and then use the 'Emsfb/v1/forms/recovery/efb set password' endpoint with the sid to set a new password.Recommendations
Update Easy Form Builder by WhiteStudio to version 4.0.12 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Form Builder