Stored Cross-Site Scripting Vulnerability in JetFormBuilder Plugin for WordPress
CVE-2026-97342
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-97342?
The JetFormBuilder plugin for WordPress has a vulnerability that allows attackers to exploit insufficient input sanitization and output escaping. This issue affects all versions up to 3.6.5.4, permitting unauthenticated users to inject malicious scripts via the 'choice' post meta during Insert/Update Post actions. By utilizing the wp_ajax_nopriv_jet_form_builder_submit endpoint, attackers can store injected payloads in post metadata, which may then execute when users access affected pages. The exploitation occurs due to the Select Field block template rendering the stored content without proper escaping, presenting a significant risk to site integrity.
Affected Version(s)
JetFormBuilder β Dynamic Blocks Form Builder 0 <= 3.6.5.4