Whitestudio
Whitestudio Easy Form Builder: vulnerabilidades y CVE
Whitestudio Easy Form Builder tiene 12 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses8
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85123 | Media (5.3) | 0.30% | — | 18 sept 2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress… |
| CVE-2026-85122 | Alta (8.8) | 0.51% | — | 18 sept 2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary… |
| CVE-2026-59517 | Alta (7.1) | 0.25% | — | 23 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. |
| CVE-2026-13439 | Crítica (9.8) | 0.71% | — | 21 jul 2026 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using… |
| CVE-2026-42747 | Crítica (9.3) | 0.40% | — | 27 may 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder:… |
| CVE-2025-14067 | Media (5.3) | 0.25% | — | 14 feb 2026 | The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for… |
| CVE-2026-22472 | Media (4.3) | 0.21% | — | 22 ene 2026 | Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <=… |
| CVE-2025-67577 | Media (5.3) | 0.25% | — | 9 dic 2025 | Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <=… |
| CVE-2025-54678 | Crítica (9.3) | 0.30% | — | 14 ago 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder:… |
| CVE-2024-12112 | Media (6.4) | 0.25% | — | 8 ene 2025 | The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the… |
| CVE-2024-30535 | Alta (8.5) | 0.49% | — | 31 mar 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4. |
| CVE-2022-3906 | Media (4.8) | 0.40% | — | 12 dic 2022 | The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.