A security flaw has been found in the Easy Form Builder by WhiteStudio plugin for WordPress, which affects all versions up to and including 4.0.11. This vulnerability lets people who are not logged into your website gain full administrator access, meaning they could take full control of your site.
The flaw exists because the plugin’s password reset feature uses a publicly visible session ID as a reset code, and also has a public page that gives out valid WordPress login tokens to any visitor. Attackers can grab the public session ID from a login form published on your site, request a password reset for any known user email linked to your site, then use that grabbed session ID to set a new password for that user, including your site’s main administrator account.
If an attacker gets administrator access, they can change your site’s content, steal information from your visitors, install harmful software, or even take your site offline completely. Only sites that have this specific Easy Form Builder plugin (version 4.0.11 or older) installed and turned on are at risk from this issue.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-13439