Reflected DOM-Based Cross-Site Scripting in JetFormBuilder Plugin for WordPress
CVE-2026-103912

4.7MEDIUM

What is CVE-2026-103912?

The JetFormBuilder plugin for WordPress is susceptible to reflected DOM-based cross-site scripting (XSS) due to inadequate input sanitization and output escaping. This vulnerability is triggered through the '<attacker-chosen query var name matching the preset's query_var setting>' parameter, impacting all versions up to and including 3.6.6. Attackers can exploit this weakness to inject arbitrary scripts into web pages, which can execute if users are convinced to engage with compromised links. This risk arises particularly on pages with forms containing text fields that utilize a query_var Dynamic Preset, a common feature within the plugin. Proper sanitization and filtering methods are essential to mitigate such security risks.

Affected Version(s)

JetFormBuilder β€” Dynamic Blocks Form Builder 0 <= 3.6.6

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zenith-sec
.