Junglewise Threat Intelligence

CVE-2026-54195: Jetmonsters JetFormBuilder unauthenticated XSS

CVE-2026-54195 · Severity: high · CVSS 7.1 · Published 2026-06-17

Technologies: Crocoblock JetFormBuilder. Vendors: Crocoblock.

Executive brief

JetFormBuilder is a WordPress plugin used to create and manage custom forms. A security vulnerability allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the JetFormBuilder plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts. Exploitation requires user interaction, such as a privileged user clicking a malicious link or visiting a crafted page. Successful exploitation can lead to the execution of malicious payloads in the context of the victim's browser, potentially resulting in session hijacking or site defacement. The issue is fixed in version 3.6.1.

Affected products

  • Jetmonsters (Crocoblock) JetFormBuilder <= 3.6.0.1

Timeline

  • 2026-05-20: other: Vulnerability reported by researcher daroo
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date
  • 2026-06-17: patched: Patch available in version 3.6.1

References

Related threats