{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/whitestudio/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-13439"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Easy Form Builder by WhiteStudio plugin for WordPress \u003c= 4.0.11"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","privilege-escalation","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WhiteStudio","WordPress"],"content_html":"\u003cp\u003eThe Easy Form Builder by WhiteStudio plugin for WordPress is affected by a critical unauthenticated privilege escalation vulnerability, tracked as CVE-2026-13439, in versions up to and including 4.0.11. This flaw stems from a insecure password recovery mechanism that relies on a publicly visible session identifier ('sid') acting as a password reset token. Attackers can leverage this by first scraping the 'sid' from a published login form page. They then submit a password recovery request for any known user email, including administrative accounts, via the \u003ccode\u003eEmsfb/v1/forms/message/add\u003c/code\u003e endpoint. A publicly accessible nonce refresh endpoint, \u003ccode\u003eEmsfb/v1/nonce/refresh\u003c/code\u003e, further aids exploitation by providing valid WordPress REST nonces to unauthenticated users. Finally, by calling \u003ccode\u003eEmsfb/v1/forms/recovery/efb_set_password\u003c/code\u003e with the harvested 'sid' and a valid nonce, an attacker can set an arbitrary new password for the target account, ultimately gaining full administrator access to the WordPress site. This vulnerability poses a severe risk, enabling complete site compromise without requiring any prior authentication.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInformation Gathering\u003c/strong\u003e: An unauthenticated attacker accesses a WordPress site using the Easy Form Builder plugin and scrapes the publicly visible session identifier ('sid') from a published login form page.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePassword Recovery Request\u003c/strong\u003e: The attacker crafts and sends a request to the \u003ccode\u003eEmsfb/v1/forms/message/add\u003c/code\u003e endpoint, initiating a password recovery process for a known WordPress user's email address, targeting an administrator account if possible.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNonce Acquisition\u003c/strong\u003e: The attacker accesses the publicly accessible \u003ccode\u003eEmsfb/v1/nonce/refresh\u003c/code\u003e endpoint to obtain a valid WordPress REST nonce without needing authentication.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePassword Reset Execution\u003c/strong\u003e: With the scraped 'sid' and the acquired valid nonce, the attacker sends a request to the \u003ccode\u003eEmsfb/v1/forms/recovery/efb_set_password\u003c/code\u003e endpoint, providing a new arbitrary password.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivilege Escalation\u003c/strong\u003e: The plugin's flawed logic processes the request, resetting the target user's password to the attacker-defined value.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdministrative Access\u003c/strong\u003e: The attacker uses the newly set password to log in as the compromised user, effectively gaining full administrator access to the WordPress site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13439 grants unauthenticated attackers full administrator control over the affected WordPress site. This allows them to execute arbitrary code, manipulate website content, deploy malicious plugins, steal sensitive data, deface the website, or use it as a platform for further attacks. The high CVSS v3.1 base score of 9.8 reflects the critical nature of this vulnerability, indicating ease of exploitation and severe consequences without any user interaction or authentication required. Any organization running the vulnerable plugin faces complete compromise of their WordPress installation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch the Easy Form Builder by WhiteStudio plugin to a version beyond 4.0.11 to remediate CVE-2026-13439.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-13439 Exploitation Attempts via Password Reset Endpoint\u0026quot; to your SIEM for early detection of exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging for HTTP POST requests to the \u003ccode\u003eEmsfb/v1/forms/recovery/efb_set_password\u003c/code\u003e, \u003ccode\u003eEmsfb/v1/forms/message/add\u003c/code\u003e, and \u003ccode\u003eEmsfb/v1/nonce/refresh\u003c/code\u003e endpoints.\u003c/li\u003e\n\u003cli\u003eRegularly review web server access logs for suspicious activity, particularly involving the IOCs \u003ccode\u003eEmsfb/v1/forms/recovery/efb_set_password\u003c/code\u003e, \u003ccode\u003eEmsfb/v1/forms/message/add\u003c/code\u003e, and \u003ccode\u003eEmsfb/v1/nonce/refresh\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T06:19:35Z","date_published":"2026-07-21T06:19:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-easy-form-builder-privesc/","summary":"An unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.","title":"WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)","url":"https://feed.craftedsignal.io/briefs/2026-07-easy-form-builder-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - WhiteStudio","version":"https://jsonfeed.org/version/1.1"}