PT-2026-8046 · WordPress · Easy Form Builder

Itthidej Aramsri

·

Published

2026-02-14

·

Updated

2026-02-14

·

CVE-2025-14067

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easy Form Builder plugin for WordPress versions through 3.9.3
Description The Easy Form Builder plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on multiple AJAX actions. Attackers with Subscriber-level access or higher can retrieve sensitive form response data, including messages, admin replies, and user information. The issue stems from a logic error in the authorization check, where the AND operator (&&) was used instead of the OR operator (||). The vulnerable AJAX actions allow retrieval of data without proper authorization.
Recommendations Update the Easy Form Builder plugin to a version later than 3.9.3.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14067

Affected Products

Easy Form Builder