CVE-2026-85123: Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type Confusion
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Easy Form Builder by WhiteStudioto a version that resolves this vulnerability.Fixed in 4.2.0
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
Sites using the WhiteStudio Easy Form Builder WordPress plugin in versions before 4.2.0 are affected. The issue is relevant even when the site owner has disabled WordPress user registration.
What does an attacker need to exploit it?
An attacker does not need to authenticate. They can exploit the issue by submitting a value that is not validated against the stored configuration for certain plugin form types, enabling account creation.
What is the practical impact if exploitation succeeds?
An unauthenticated attacker can create a WordPress account despite registration being disabled. The provided information does not state what role or privileges the created account receives.