CVE-2026-85122: Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Easy Form Builder by WhiteStudioto a version that resolves this vulnerability.Fixed in 4.2.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user can submit crafted content through affected Easy Form Builder form types. Exploitation does not require a WordPress account.
When does the stored payload execute?
The arbitrary submitted content is stored and rendered without escaping on an admin page. An administrator or other user who accesses that affected admin page may trigger the stored XSS.
Which versions are affected?
Easy Form Builder versions before 4.2.0 are affected. The reported vulnerable range includes 4.0.0 through 4.1.3.