Junglewise Threat Intelligence

CVE-2026-54196: Jetmonsters JetFormBuilder privilege escalation in WordPress plugin

CVE-2026-54196 · Severity: medium · CVSS 6.8 · Published 2026-06-17

Technologies: Crocoblock JetFormBuilder. Vendors: Crocoblock.

Executive brief

JetFormBuilder is a WordPress plugin used to create and manage complex forms. A security flaw allows users with low-level 'Subscriber' accounts to elevate their permissions, potentially gaining full administrative control over the website. This could lead to unauthorized data access, site defacement, or complete service disruption.

Technical details

A privilege escalation vulnerability exists in the JetFormBuilder plugin for WordPress due to incorrect privilege assignment (CWE-266). The flaw allows an authenticated attacker with Subscriber-level permissions to escalate their privileges to a higher level, potentially gaining full administrative access. The attack vector is network-based, though it requires a low-privileged account and involves high complexity (AC:H). The vulnerability is addressed in version 3.6.1.1.

Affected products

  • Jetmonsters (Crocoblock) JetFormBuilder <= 3.6.1

Timeline

  • 2026-05-28: other: Reported by researcher Baikuya
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date
  • 2026-06-17: patched: Patch released in version 3.6.1.1

References

Related threats