Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code Execution
Strategic Overview
<= 5.0.0CVE-2025-8420Vulnerability Overview
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called
Technical Analysis
REMEDIATION: Update to version 5.0.1, or a newer patched version --- IDENTIFIER: CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')) The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. eval).
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C