rootpwn

critical · CVSS v3 9.1

CVE-2026-85123

The Easy Form Builder plugin for WordPress fails to properly validate submitted values against stored configurations for certain form types.

Overview

The Easy Form Builder plugin for WordPress fails to properly validate submitted values against stored configurations for certain form types. This oversight allows unauthenticated attackers to create unauthorized WordPress accounts on target sites where user registration has been explicitly disabled by the administrator. The flaw undermines core site access controls and exposes the installation to potential administrative takeover.

Description

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.

Impact

This vulnerability primarily impacts the integrity and availability of the WordPress site by enabling unauthorized account creation that bypasses administrative policy. If exploited, attackers could provision high-privilege accounts, leading to full system compromise. Confidentiality is also threatened as attackers gain access to restricted areas of the application. Website administrators and organizations relying on the plugin for form management are directly affected.

Remediation

Update the Easy Form Builder plugin to version 4.2.0 or later immediately. As an interim defense, temporarily deactivate the plugin if updating is not immediately feasible. Review existing WordPress user accounts for unauthorized creations and enforce strict monitoring for new registrations.

Risk context

The vulnerability carries a critical severity rating with a CVSS v3 score of 9.1, driven by the ability for unauthenticated remote attackers to bypass registration controls. Immediate patching is strongly recommended to prevent potential exploitation.

Affected products

  • WhiteStudio Easy Form Builder < 4.2.0

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.1
CVSS v4
EPSS

wordpress plugin authentication-bypass unauthenticated account-creation cve-2026-85123 web-application

← All CVEs