Software intelligence
Important: Easy Form Builder appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
10
Latest advisory
21 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
easy-form-builder
Plugin
This catalog lists 10 known advisories affecting Easy Form Builder. The most recent was published on 21 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder <= 4.0.12 - Unauthenticated Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 21 July 2026
Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint
May allow a lower-privilege user to perform actions reserved for administrators.
Published 20 July 2026
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder <= 4.0.6 - Unauthenticated SQL Injection
May allow attackers to read or modify database contents beyond intended access.
Published 28 May 2026
Known Easy Form Builder advisories published by month.
CVE-2026-59517 · Published 21 July 2026
Affected versions: ≤ 4.0.12
CVE-2026-13439 · Published 20 July 2026
Affected versions: ≤ 4.0.11
CVE-2026-42747 · Published 28 May 2026
Affected versions: ≤ 4.0.6
CVE-2025-14067 · Published 13 February 2026
Affected versions: ≤ 3.9.3
CVE-2026-22472 · Published 6 January 2026
Affected versions: ≤ 3.9.6
CVE-2025-67577 · Published 15 December 2025
Affected versions: ≤ 3.8.20
CVE-2025-54678 · Published 7 August 2025
Affected versions: ≤ 3.8.15
CVE-2024-12112 · Published 7 January 2025
Affected versions: ≤ 3.8.8
CVE-2024-30535 · Published 29 March 2024
Affected versions: ≤ 3.7.4
CVE-2022-3906 · Published 16 November 2022
Affected versions: ≤ 3.3.8
SiteRespond Defence matches your installed Easy Form Builder version against this catalog when the Defence plugin is connected to your WordPress site.