CVE-2026-84817
largeUnauthenticated Cross-Site Scripting in JetFormBuilder WordPress Plugin
JetFormBuilder, a WordPress form-builder plugin published by Crocoblock, contains an unauthenticated cross-site scripting flaw (CWE-79) affecting all versions up to and including 3.6.5.1. Per the CVSS vector, no privileges are required to exploit it, but successful execution requires user interaction, meaning an unauthenticated attacker can trigger malicious script only by getting a victim to interact with a crafted request or affected page. When the payload runs, it executes in the victim's browser within the trusted context of the affected site (scope changed), which can enable session hijacking, unwanted actions performed as the victim, forced redirects, or disclosure of content displayed on the page; rated impact is limited for confidentiality and integrity with no direct availability loss. Any WordPress site with JetFormBuilder 3.6.5.1 or older installed and active is affected. There is no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns roughly a 0.1% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Update JetFormBuilder to the latest available release (any version newer than 3.6.5.1) on every site where the plugin is active, and verify the running version in wp-admin afterward. Until patched, prioritize public-facing pages containing forms, consider a WAF or virtual-patching rule for XSS on form-related requests, and review logs for suspicious form submissions or inbound links to your forms. Multisite administrators should confirm the plugin version on each subsite, since activation and updates may vary per site.
| Crocoblock JetFormBuilder (WordPress plugin) | <= 3.6.5.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.