« Volver al listado

Whitestudio

Whitestudio Easy Form Builder: vulnerabilidades y CVE

Whitestudio Easy Form Builder tiene 12 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses8
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85123Media (5.3)0.30%—18 sept 2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress…
CVE-2026-85122Alta (8.8)0.51%—18 sept 2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary…
CVE-2026-59517Alta (7.1)0.25%—23 jul 2026
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-13439Crítica (9.8)0.71%—21 jul 2026
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using…
CVE-2026-42747Crítica (9.3)0.40%—27 may 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder:…
CVE-2025-14067Media (5.3)0.25%—14 feb 2026
The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for…
CVE-2026-22472Media (4.3)0.21%—22 ene 2026
Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <=…
CVE-2025-67577Media (5.3)0.25%—9 dic 2025
Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <=…
CVE-2025-54678Crítica (9.3)0.30%—14 ago 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder:…
CVE-2024-12112Media (6.4)0.25%—8 ene 2025
The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the…
CVE-2024-30535Alta (8.5)0.49%—31 mar 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4.
CVE-2022-3906Media (4.8)0.40%—12 dic 2022
The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System2
  3. T1059.007 JavaScript2
  4. T1189 Drive-by Compromise2
  5. T1068 Exploitation for Privilege Escalation1
  6. T1136 Create Account1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.