VYPR
Medium severity5.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67577

CVE-2025-67577

Description

Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Easy Form Builder plugin <= 3.8.20 lacks proper access control, allowing unauthenticated attackers to exploit misconfigured security levels.

Vulnerability

Overview

The Easy Form Builder WordPress plugin (versions up to and including 3.8.20) is affected by a Missing Authorization vulnerability [1]. This is a broken access control issue where the plugin fails to properly enforce capability checks, meaning certain functions can be triggered without the appropriate permissions [1].

Exploitation

Conditions

An attacker can exploit this vulnerability without requiring authentication [1]. The missing authorization check means that any unauthenticated visitor could potentially access endpoints or actions that should be restricted to higher-privileged users, such as administrators [1]. The vulnerability is classified as Medium severity (CVSS 5.3) and has been noted as being used in mass-exploit campaigns targeting thousands of websites [1].

Impact

Successful exploitation allows an attacker to perform actions that should require higher-level access within the plugin's functionality [1]. This could include modifying form data, accessing protected submissions, or other unintended operations depending on the exact missing checks. The impact is considered low, but the ease of exploitation due to missing authentication elevates the risk [1].

Mitigation

The vendor has released version 3.8.21 which resolves the vulnerability [1]. Users are strongly advised to update immediately. For Patchstack users, auto-updates can be enabled for vulnerable plugins. If updating is not possible, users should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.