Junglewise Threat Intelligence

CVE-2026-57750: Keksdieb ez Form Calculator Premium broken access control

CVE-2026-57750 · Severity: medium · CVSS 5.3 · Published 2026-07-02

Executive brief

The ez Form Calculator Premium plugin for WordPress, which is used to create interactive cost estimation and payment forms, contains a security flaw in its access control mechanisms. An unauthorized user can bypass security checks to perform actions that should be restricted to administrators or higher-privileged users. While the impact is limited to modifying certain data rather than full site takeover, it could allow attackers to interfere with form operations or site settings.

Technical details

The ez Form Calculator Premium plugin for WordPress (versions up to and including 2.14.1.2) is vulnerable to a Broken Access Control flaw classified as CWE-862 (Missing Authorization). The vulnerability stems from a failure to implement proper authorization, authentication, or nonce checks on specific functions. A remote, unauthenticated attacker can exploit this to execute restricted actions, though the CVSS score suggests the impact is limited to integrity (unauthorized modification) without direct data leakage or availability loss. As of the advisory date, no official patch has been released.

Affected products

  • Keksdieb ez Form Calculator Premium <= 2.14.1.2

Timeline

  • 2026-01-20: other: Reported by Phat RiO
  • 2026-07-02: advisory: Published by Patchstack and NVD

References