Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Campus Directory Plugin | — | Update campus-directory plugin to version 1.9.3, or a newer patched version | Aug 28, 2025 | Aug 5, 2025 |
| Employee Staff Directory Plugin | — | Update employee-staff-directory plugin to version 4.5.3, or a newer patched version | Aug 28, 2025 | Aug 5, 2025 |
| Request A Quote Plugin | — | Update request-a-quote plugin to version 2.5.3, or a newer patched version | Aug 6, 2025 | Aug 5, 2025 |
| Software Issue Manager Plugin | — | Update software-issue-manager plugin to version 5.0.1, or a newer patched version | Aug 15, 2025 | Aug 5, 2025 |
| Wp Easy Contact Plugin | — | Update wp-easy-contact plugin to version 4.0.3, or a newer patched version | Aug 28, 2025 | Aug 5, 2025 |
| Wp Easy Events Plugin | — | Update wp-easy-events plugin to version 4.2.2, or a newer patched version | Aug 28, 2025 | Aug 5, 2025 |
| Wp Ticket Plugin | — | Update wp-ticket plugin to version 6.0.3, or a newer patched version | Aug 15, 2025 | Aug 5, 2025 |
| Youtube Showcase Plugin | — | Update youtube-showcase plugin to version 3.5.3, or a newer patched version | Sep 26, 2025 | Aug 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub