Sensitive Information Exposure in e-shot Form Builder Plugin for WordPress
CVE-2026-3546
5.3MEDIUM
What is CVE-2026-3546?
The e-shot Form Builder Plugin for WordPress is compromised due to insufficient checks in the eshot_form_builder_get_account_data() function, which lacks capability restrictions and nonce verification. This vulnerability allows authenticated users, even those with minimal access rights, to retrieve sensitive information such as the e-shot API token and associated subaccount data. The exposed data can enable unauthorized access to an individual’s e-shot platform account, posing a significant risk to users' personal and business information.
Affected Version(s)
e-shot 0 <= 1.0.2