Executive brief
Easy Form Builder, a WordPress plugin used to create and manage website forms, contains a critical security vulnerability. An attacker can use this flaw to extract sensitive information from the website's database without needing any login credentials. This could lead to the exposure of customer data, administrative details, or other confidential site information.
Technical details
A Blind SQL Injection vulnerability exists in the Easy Form Builder plugin (versions up to and including 4.0.6) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an unauthenticated attacker to send crafted requests to the server and infer data from the database based on the application's response patterns. This is a network-based attack that requires no user interaction or prior authentication. Successful exploitation can lead to high confidentiality impact and a partial impact on availability. Users are advised to update to a version newer than 4.0.6 if available.
Affected products
- hassantafreshi Easy Form Builder n/a through 4.0.6
Timeline
- 2026-05-27: disclosed: Initial publication of the CVE record.
- 2026-05-27: advisory: Advisory published by Patchstack.