Junglewise Threat Intelligence

CVE-2022-4997: JetFormBuilder Stripe Gateway SQL injection in payment token

CVE-2022-4997 · Severity: high · CVSS 8.6 · Published 2026-09-23

Vendors: Crocoblock.

Executive brief

JetFormBuilder Stripe Gateway is a WordPress plugin that handles Stripe payment processing for forms. Before version 1.1.0, it fails to properly sanitize payment tokens before using them in database queries, allowing anyone to inject SQL commands and extract sensitive data such as password hashes without authentication.

Technical details

Unauthenticated blind SQL injection vulnerability in the payment token parameter. The plugin constructs SQL statements without proper escaping or parameterized queries, allowing attackers to extract arbitrary database content via time-based or error-based inference. No authentication or user interaction required beyond crafting a malicious request.

Affected products

  • Crocoblock JetFormBuilder Stripe Gateway before 1.1.0

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: version 1.1.0 available

References