CVE-2026-85123: Unknown Easy Form Builder By Whitestudio

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.

Affected products

  • Unknown Easy Form Builder By Whitestudio: from 4.0.0, before 4.2.0 (fixed in 4.2.0)

Published 2026-09-18. Last modified 2026-09-18.