Junglewise Threat Intelligence

CVE-2026-13439: WhiteStudio Easy Form Builder unauthenticated privilege escalation

CVE-2026-13439 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Executive brief

The Easy Form Builder plugin for WordPress, used to create custom contact and data entry forms, contains a critical security flaw that allows anyone to take over any user account. An attacker can exploit a weakness in the password reset process to change the password of any user, including site administrators. This could lead to a total loss of control over the website and exposure of all stored data.

Technical details

The Easy Form Builder plugin for WordPress is vulnerable to unauthenticated privilege escalation due to an insecure password recovery flow. The vulnerability stems from the use of a publicly-visible session identifier ('sid') as the password reset token stored in the 'wp_emsfb_temp_links' table. An attacker can obtain a valid REST nonce via the 'Emsfb/v1/nonce/refresh' endpoint, scrape the 'sid' from a public form page, and initiate a recovery request for a target email via 'Emsfb/v1/forms/message/add'. By then calling the 'Emsfb/v1/forms/recovery/efb_set_password' endpoint with the known 'sid', the attacker can set a new password for the target account. This issue affects versions up to and including 4.0.11 and is addressed in version 4.0.12.

Affected products

  • WhiteStudio Easy Form Builder by WhiteStudio up to, and including, 4.0.11

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References