CVE-2026-85122
Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
| Vendor | unknown |
| Product | easy form builder by whitestudio |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown easy form builder by whitestudio
Be the first to know when new unknown vulnerabilities affecting unknown easy form builder by whitestudio are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Easy Form Builder by WhiteStudio
4.0.0 < 4.2.0
References
Credits
Civitasmass WPScan