WP Vulnerability WatchVulnerability data as of September 17, 2026

Vulnerability alerts / September 16, 2026

Vulnerability in JetFormBuilder — Dynamic Blocks Form Builder — CVE-2026-12793

CriticalSeverity
CVSS 9.8
0.4%Estimated exploit probability
EPSS
80,000+ sitesInstalls
3.6.2.1Fixed in

What to do now

Update JetFormBuilder — Dynamic Blocks Form Builder to 3.6.2.1 or later.

Affected versions

  • Everything up to and including 3.6.2

Affected: JetFormBuilder — Dynamic Blocks Form Builder (plugin, jetformbuilder)

Check: The plugin on wordpress.org / Our record for JetFormBuilder — Dynamic Blocks Form Builder

What the vulnerability is

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts