CVE-2026-85122 PUBLISHED

Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion

Assigner: WPScan
Reserved: 03.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.

Product Status

Vendor Unknown
Product Easy Form Builder by WhiteStudio
Versions Default: unaffected
  • affected from 4.0.0 to 4.2.0 (excl.)

Credits

  • Civitasmass finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE