Back

HIGH

Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion

Published Sep 18, 2026

Description

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Sep 18, 2026
Updated Sep 18, 2026
Reserved Sep 3, 2026

CISA Vulnrichment

Updated Sep 18, 2026

NVD

Status Deferred
Modified Sep 18, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Sep 18, 2026
Updated Sep 18, 2026

GitHub

No data