Unauthenticated Privilege Escalation in Easy Form Builder by WhiteStudio for WordPress
CVE-2026-13439
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-13439?
The Easy Form Builder plugin by WhiteStudio for WordPress contains a serious vulnerability where unauthenticated users can exploit a flawed password recovery process. The plugin improperly uses a publicly-visible session identifier ('sid') as a password reset token, while also exposing a nonce refresh endpoint. This allows attackers to reset the passwords of any WordPress users, including administrators, by leveraging the publicly exposed sid and executing a series of requests to gain unauthorized access.
Affected Version(s)
Easy Form Builder by WhiteStudio β Drag & Drop Form Builder 0 <= 4.0.11