Stored Cross-Site Scripting Vulnerability in JetFormBuilder Plugin for WordPress
CVE-2026-97342

7.2HIGH

What is CVE-2026-97342?

The JetFormBuilder plugin for WordPress has a vulnerability that allows attackers to exploit insufficient input sanitization and output escaping. This issue affects all versions up to 3.6.5.4, permitting unauthenticated users to inject malicious scripts via the 'choice' post meta during Insert/Update Post actions. By utilizing the wp_ajax_nopriv_jet_form_builder_submit endpoint, attackers can store injected payloads in post metadata, which may then execute when users access affected pages. The exploitation occurs due to the Select Field block template rendering the stored content without proper escaping, presenting a significant risk to site integrity.

Affected Version(s)

JetFormBuilder β€” Dynamic Blocks Form Builder 0 <= 3.6.5.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO
.