Junglewise Threat Intelligence

CVE-2026-59517: hassantafreshi Easy Form Builder unauthenticated XSS

CVE-2026-59517 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: Hassan Tafreshi Easy Form Builder. Vendors: Hassan Tafreshi.

Executive brief

Easy Form Builder is a WordPress plugin used to create and manage custom forms on websites. A security vulnerability in versions 4.0.12 and earlier allows unauthenticated attackers to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could steal session information, redirect users to malicious websites, or deface the site.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Easy Form Builder plugin for WordPress (versions up to and including 4.0.12). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a malicious payload that is subsequently executed in the browser of a victim, typically a site administrator, when they view the affected page. Successful exploitation requires minimal user interaction and can lead to session hijacking or unauthorized actions performed in the context of the victim's browser. The issue is resolved in version 4.0.13.

Affected products

  • hassantafreshi Easy Form Builder <= 4.0.12

Timeline

  • 2026-06-28: other: Vulnerability reported by researcher dutafi
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset
  • 2026-07-23: patched: Patch available in version 4.0.13

References

Related threats