Subscriber Privilege Escalation Vulnerability in JetFormBuilder by WordPress
CVE-2026-54196
6.8MEDIUM
What is CVE-2026-54196?
A design flaw in JetFormBuilder versions 3.6.1 and earlier allows attackers to exploit subscriber-level privileges, granting unauthorized access to areas where standard users should be restricted. This vulnerability poses a significant risk, allowing malicious users to perform actions that are typically reserved for higher-privilege accounts. Websites utilizing this plugin should update to the latest version to mitigate any potential risks associated with this vulnerability.
Affected Version(s)
JetFormBuilder <= 3.6.1