CVE-2026-13439
The Easy Form Builder plugin for WordPress lets anyone reset any user’s password without logging in. By using a public session ID and a nonce endpoint, attackers can set a new password for any account, including administrators. This gives full control over the site.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress sites using the Easy Form Builder plugin, versions 4.0.11 and earlier.
Real-world impact
An attacker can reset any WordPress user’s password, including administrators, and then log in with full control over the site.
Why this severity
The CVSS score is 9.8 because the flaw requires no authentication, has no user interaction, and allows complete compromise of the site.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
How it’s attacked
References & advisories
- plugins.trac.wordpress.org/browser/easy-form-builder/t…
- plugins.trac.wordpress.org/browser/easy-form-builder/t…
- plugins.trac.wordpress.org/browser/easy-form-builder/t…
- plugins.trac.wordpress.org/browser/easy-form-builder/t…
- plugins.trac.wordpress.org/browser/easy-form-builder/t…
- plugins.trac.wordpress.org/changeset/3588226/easy-form…
- plugins.trac.wordpress.org/changeset
- wordfence.com/threat-intel/vulnerabilitie…