๐Ÿ” CVE Alert

CVE-2026-85122

UNKNOWN 0.0

Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.

Vendor unknown
Product easy form builder by whitestudio
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown easy form builder by whitestudio

Be the first to know when new unknown vulnerabilities affecting unknown easy form builder by whitestudio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Easy Form Builder by WhiteStudio
4.0.0 < 4.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7263f875-3ff3-410a-94b0-fa4b3694d356/

Credits

Civitasmass WPScan