PT-2026-8046 · WordPress · Easy Form Builder
Itthidej Aramsri
·
Published
2026-02-14
·
Updated
2026-02-14
·
CVE-2025-14067
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Form Builder plugin for WordPress versions through 3.9.3
Description
The Easy Form Builder plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on multiple AJAX actions. Attackers with Subscriber-level access or higher can retrieve sensitive form response data, including messages, admin replies, and user information. The issue stems from a logic error in the authorization check, where the AND operator (&&) was used instead of the OR operator (||). The vulnerable AJAX actions allow retrieval of data without proper authorization.
Recommendations
Update the Easy Form Builder plugin to a version later than 3.9.3.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Form Builder