Executive brief
JetFormBuilder is a WordPress plugin used to create and manage complex forms. A security flaw allows users with low-level 'Subscriber' accounts to elevate their permissions, potentially gaining full administrative control over the website. This could lead to unauthorized data access, site defacement, or complete service disruption.
Technical details
A privilege escalation vulnerability exists in the JetFormBuilder plugin for WordPress due to incorrect privilege assignment (CWE-266). The flaw allows an authenticated attacker with Subscriber-level permissions to escalate their privileges to a higher level, potentially gaining full administrative access. The attack vector is network-based, though it requires a low-privileged account and involves high complexity (AC:H). The vulnerability is addressed in version 3.6.1.1.
Affected products
- Jetmonsters (Crocoblock) JetFormBuilder <= 3.6.1
Timeline
- 2026-05-28: other: Reported by researcher Baikuya
- 2026-06-16: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date
- 2026-06-17: patched: Patch released in version 3.6.1.1