Vulnerability in JetFormBuilder — Dynamic Blocks Form Builder — WF-b0fe7d29-118f-42fb-9e48-6217faaa689b
What to do now
Update JetFormBuilder — Dynamic Blocks Form Builder to 3.6.2.1 or later.
Affected versions
- Everything up to and including 3.6.2
Affected: JetFormBuilder — Dynamic Blocks Form Builder (plugin, jetformbuilder)
What the vulnerability is
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'do_action' function in the 'Update_Options' action class in all versions up to, and including, 3.6.2. This makes it possible for unauthenticated attackers to modify JetEngine Options Page values when an administrator has configured a form with the "Update Options" post-submission action. The vulnerability requires that both JetFormBuilder and JetEngine are installed and active, and that an administrator has specifically configured a form with the Update Options action.