ZeroHour

CVE-2026-19858

moderate

Unauthenticated Sensitive Data Exposure in JetFormBuilder WordPress Plugin

CVSS 3.1
7.5 high
EPSS
<1%p24
Published
()
Modified
AI analysis

JetFormBuilder — Dynamic Blocks Form Builder before 3.6.5.2 fails to enforce authorisation checks when resolving request-derived data during page rendering (CWE-200). An unauthenticated attacker can send crafted requests to a site using the plugin's form/page rendering features and have arbitrary user, post, and term properties and metadata returned. This exposes sensitive data such as user password hashes, private and draft post content, and secrets that other plugins store in metadata. All WordPress sites running a version of the plugin below 3.6.5.2 are affected. No public proof of concept, exploitation reports, or CISA KEV listing are known at this time.

What to do: Update JetFormBuilder to version 3.6.5.2 or later as soon as possible. Since the flaw exposes arbitrary metadata, administrators should review whether sensitive secrets or credentials are stored in user, post, or term metadata by JetFormBuilder or other plugins and rotate any exposed values. A WAF rule blocking unauthenticated access to the plugin's front-end/AJAX data-resolution endpoints may provide interim mitigation, but the patch is the definitive fix.

Affected
Crocoblock JetFormBuilder — Dynamic Blocks Form Builder (WordPress plugin)All versions before 3.6.5.2
Estimated exposure
moderatetens of thousands of sites (roughly 70,000+ active installs of the free plugin) — WordPress.org shows JetFormBuilder with on the order of 70,000+ active installations, and Pro deployments and sites not auto-updating add unknown additional exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.

Ecosystems
WordPress
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.