WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / September 3, 2026

Vulnerability in JetFormBuilder — Dynamic Blocks Form Builder — WF-b0fe7d29-118f-42fb-9e48-6217faaa689b

MediumSeverity
CVSS 5.3
Estimated exploit probability
EPSS
80,000+ sitesInstalls
3.6.2.1Fixed in

What to do now

Update JetFormBuilder — Dynamic Blocks Form Builder to 3.6.2.1 or later.

Affected versions

  • Everything up to and including 3.6.2

Affected: JetFormBuilder — Dynamic Blocks Form Builder (plugin, jetformbuilder)

Check: The plugin on wordpress.org / Our record for JetFormBuilder — Dynamic Blocks Form Builder

What the vulnerability is

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'do_action' function in the 'Update_Options' action class in all versions up to, and including, 3.6.2. This makes it possible for unauthenticated attackers to modify JetEngine Options Page values when an administrator has configured a form with the "Update Options" post-submission action. The vulnerability requires that both JetFormBuilder and JetEngine are installed and active, and that an administrator has specifically configured a form with the Update Options action.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/b0fe7d29-118f-42fb-9e48-6217faaa689b
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts