Unauthenticated Privilege Escalation in Easy Form Builder by WhiteStudio for WordPress
CVE-2026-13439

9.8CRITICAL

What is CVE-2026-13439?

The Easy Form Builder plugin by WhiteStudio for WordPress contains a serious vulnerability where unauthenticated users can exploit a flawed password recovery process. The plugin improperly uses a publicly-visible session identifier ('sid') as a password reset token, while also exposing a nonce refresh endpoint. This allows attackers to reset the passwords of any WordPress users, including administrators, by leveraging the publicly exposed sid and executing a series of requests to gain unauthorized access.

Affected Version(s)

Easy Form Builder by WhiteStudio – Drag & Drop Form Builder 0 <= 4.0.11

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CHOIGYEONGMIN
.