CVE-2026-13439: WordPress Easy Form Builder Unauthenticated Privilege Escalation (CVSS 9.8)
ID: 917630ae-e3f8-5613-a3dd-e422766dae08
STIX ID: report--917630ae-e3f8-5613-a3dd-e422766dae08
Feed Name: CosmicBytez Labs
Threat Score
Critical CVE-2026-13439: an unauthenticated privilege-escalation vulnerability in the Easy Form Builder (<= 4.0.11) WordPress plugin allows attackers to use a publicly visible session identifier (sid) as a password reset token to gain administrator access and fully compromise sites; the advisory includes technical details, detection commands, impact analysis, and remediation guidance (update or remove plugin, audit and reset admin accounts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
