Reflected DOM-Based Cross-Site Scripting in JetFormBuilder Plugin for WordPress
CVE-2026-103912
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-103912?
The JetFormBuilder plugin for WordPress is susceptible to reflected DOM-based cross-site scripting (XSS) due to inadequate input sanitization and output escaping. This vulnerability is triggered through the '<attacker-chosen query var name matching the preset's query_var setting>' parameter, impacting all versions up to and including 3.6.6. Attackers can exploit this weakness to inject arbitrary scripts into web pages, which can execute if users are convinced to engage with compromised links. This risk arises particularly on pages with forms containing text fields that utilize a query_var Dynamic Preset, a common feature within the plugin. Proper sanitization and filtering methods are essential to mitigate such security risks.
Affected Version(s)
JetFormBuilder β Dynamic Blocks Form Builder 0 <= 3.6.6