PT-2026-61826 · Whitestudio · Easy Form Builder

·

CVE-2026-13439

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easy Form Builder by WhiteStudio versions prior to 4.0.12
Description An unauthenticated privilege escalation allows attackers to gain administrator access. The issue stems from the password recovery flow using a publicly-visible session identifier sid as the password reset token stored in wp emsfb temp links. This is combined with a publicly-accessible nonce refresh endpoint 'Emsfb/v1/nonce/refresh' that provides valid WordPress REST nonces to unauthenticated visitors. An attacker can scrape the sid from a published login form page, submit a recovery request for a known user email via the 'Emsfb/v1/forms/message/add' endpoint, and then use the 'Emsfb/v1/forms/recovery/efb set password' endpoint with the sid to set a new password.
Recommendations Update Easy Form Builder by WhiteStudio to version 4.0.12 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13439

Affected Products

Easy Form Builder