CVE-2026-57750: Unauthenticated Access Control Flaw in ez Form Calculator Premium ≤ 2.14.1.2
A security vulnerability exists in ez Form Calculator Premium versions 2.14.1.2 and earlier that allows attackers to modify data without authentication. The flaw stems from insufficient access controls, meaning anyone with network access—no login required—can potentially alter form submissions or configurations. This is classified as a medium-severity issue because while the integrity of data can be compromised, there is no exposure of sensitive information or service disruption in the vulnerability itself.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-862
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-02 / 2026-07-02
NVD description (verbatim)
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-57750 is an unauthenticated broken access control vulnerability (CWE-862) affecting ez Form Calculator Premium through version 2.14.1.2. The application fails to properly enforce authorization checks on sensitive endpoints, allowing an unauthenticated network attacker to issue requests that modify protected resources. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) indicates network-accessible attack surface, low complexity, no authentication barrier, and impact limited to data integrity without confidentiality loss or availability disruption.
Business impact
Organizations relying on ez Form Calculator Premium for data collection, customer submissions, or internal workflow automation face a risk of unauthorized modification of submitted forms and stored data. This could lead to corrupted records, false data entries in backend systems, compliance violations if audit trails are altered, and potential liability if customer or transactional data is tampered with. The reputational cost of data integrity breaches—even without data theft—can be significant, particularly if customers or regulators discover that form submissions were modified post-submission.
Affected systems
ez Form Calculator Premium versions 2.14.1.2 and earlier are confirmed affected. Organizations should verify their current deployment version immediately. Check WordPress plugin repositories, your admin dashboard, and any custom or air-gapped deployments to confirm whether you are running a vulnerable version. Patch availability and supported upgrade paths should be verified against the vendor's official advisory.
Exploitability
This vulnerability has a low barrier to exploitation: it requires only network access and no authentication. An attacker can craft HTTP requests to the vulnerable endpoints without any credentials or special tools. However, exploitation requires knowledge of the specific endpoints and parameters that lack proper authorization checks. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting active exploitation in the wild has not been documented at publication time, though this status can change.
Remediation
Immediately upgrade ez Form Calculator Premium to a patched version beyond 2.14.1.2. Consult the vendor's security advisory for the specific minimum version number that resolves CWE-862. If you cannot upgrade immediately, implement network-level controls such as IP whitelisting, WAF rules to restrict access to form endpoints, or temporarily disabling the plugin until a patch is applied. Review server logs and form submission records for signs of unauthorized modifications.
Patch guidance
Contact ez Form Calculator Premium vendor support or check their official website for the patched version release. Verify the patch version against the vendor's advisory before deploying. Test the update in a staging environment to ensure compatibility with your WordPress version and other active plugins. Once validated, schedule the upgrade during a maintenance window and monitor form submission functionality post-patch. Keep the plugin updated to receive future security maintenance.
Detection guidance
Monitor HTTP request logs for unusual POST/PUT requests to form endpoints without corresponding authentication sessions. Check for HTTP 403 (Forbidden) errors that may indicate failed authorization—repeated attempts suggest probing. Audit form data for unexpected modifications, particularly timestamp mismatches or field changes that do not correlate to legitimate submissions. Use Web Application Firewall (WAF) rules to log and block unauthenticated requests to sensitive form processing paths. Consider enabling form submission versioning or checksums to detect tampering after the fact.
Why prioritize this
Despite a medium CVSS score, this vulnerability should be prioritized because it directly affects data integrity in form submissions—a core business function for many organizations. The absence of authentication creates a low friction attack surface. If your organization relies on ez Form Calculator Premium for customer intake, lead generation, survey collection, or internal workflows, the risk of silent data corruption justifies prompt remediation. Delay increases exposure window and audit/compliance risk.
Risk score, explained
The CVSS 3.1 score of 5.3 (MEDIUM) reflects the network-accessible, low-complexity attack surface (AV:N/AC:L/PR:N) balanced against limited impact scope. No confidentiality impact (C:N) and no availability impact (A:N) prevent a higher rating, but the integrity impact (I:L) and unauthenticated nature warrant medium severity. Organizations handling sensitive customer data or regulated information should consider their own risk context and treat this as higher priority than the baseline score suggests.
Frequently asked questions
Do I need to be authenticated to exploit this vulnerability?
No. The vulnerability is unauthenticated broken access control, meaning attackers do not need valid credentials. Any network-connected entity can potentially craft requests to modify form data.
Is my data exposed or leaked if this vulnerability is exploited?
The vulnerability itself does not expose confidentiality—attackers cannot read sensitive data directly. However, they can modify data integrity, which could lead to corrupted records or false submissions. If attackers alter forms containing PII, downstream systems may store compromised data.
Is this vulnerability being actively exploited in the wild?
This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed widespread active exploitation at publication. However, the lack of KEV status does not guarantee safety; exploitation may exist outside public awareness.
What should I do if I cannot upgrade immediately?
Implement mitigating controls such as network access restrictions (firewall rules, VPN requirement), WAF rules to block suspicious requests, or temporary plugin disablement. Review logs for signs of tampering and plan an urgent upgrade window.
This analysis is provided for informational purposes and does not constitute professional security advice. Verify all technical details, patch version numbers, and affected product versions against the official vendor advisory before taking remediation action. Risk assessment should account for your organization's specific deployment, data sensitivity, and regulatory obligations. The absence of active exploitation (KEV status) at publication does not guarantee future safety. Always test patches in a non-production environment before deploying to production systems. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2022-42479MEDIUMMissing Authorization in TemplateHouse Soledad – MEDIUM Severity Access Control Bypass
- CVE-2022-45813MEDIUMBeRocket Advanced AJAX Product Filters Missing Authorization Flaw
- CVE-2023-25969MEDIUMMissing Authorization in ThemeHunk Contact Form Plugin
- CVE-2023-32959MEDIUMMetroStore Missing Authorization Vulnerability – Patch Guide
- CVE-2024-24709MEDIUMShareaholic Missing Authorization Vulnerability – Update Required
- CVE-2024-31435MEDIUMMissing Authorization in Inisev Social Media & Share Icons Plugin—Patch Guidance
- CVE-2024-33685MEDIUMMissing Authorization in Jegstudio Startupzy 1.1.1 – MEDIUM Severity Vulnerability
- CVE-2024-33909MEDIUMMissing Authorization in Avirtum iPages Flipbook – CVSS 5.3 Patch Guide