CVE-2026-19858
moderateUnauthenticated Sensitive Data Exposure in JetFormBuilder WordPress Plugin
JetFormBuilder — Dynamic Blocks Form Builder before 3.6.5.2 fails to enforce authorisation checks when resolving request-derived data during page rendering (CWE-200). An unauthenticated attacker can send crafted requests to a site using the plugin's form/page rendering features and have arbitrary user, post, and term properties and metadata returned. This exposes sensitive data such as user password hashes, private and draft post content, and secrets that other plugins store in metadata. All WordPress sites running a version of the plugin below 3.6.5.2 are affected. No public proof of concept, exploitation reports, or CISA KEV listing are known at this time.
What to do: Update JetFormBuilder to version 3.6.5.2 or later as soon as possible. Since the flaw exposes arbitrary metadata, administrators should review whether sensitive secrets or credentials are stored in user, post, or term metadata by JetFormBuilder or other plugins and rotate any exposed values. A WAF rule blocking unauthenticated access to the plugin's front-end/AJAX data-resolution endpoints may provide interim mitigation, but the patch is the definitive fix.
| Crocoblock JetFormBuilder — Dynamic Blocks Form Builder (WordPress plugin) | All versions before 3.6.5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.
- Ecosystems
- WordPress
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.