Executive brief
JetFormBuilder is a WordPress plugin used to create and manage web forms on websites. An unauthenticated attacker can inject malicious scripts into affected sites that steal visitor data, hijack user accounts, or redirect users to phishing pages. The vulnerability affects all versions up to 3.6.5.1 and requires user interaction to exploit, but can be delivered at scale through mass-exploit campaigns.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability in JetFormBuilder versions ≤ 3.6.5.1. The plugin fails to properly sanitize and validate user input, allowing attackers to inject arbitrary JavaScript code that executes in the context of a victim's browser. The vulnerability requires unauthenticated access but may require user interaction (such as clicking a malicious link or visiting a crafted page) for successful exploitation. An attacker can steal session cookies, credentials, or perform actions on behalf of the victim. The issue has been patched in version 3.6.5.2 or later.
Affected products
- Crocoblock JetFormBuilder 3.6.5.1 and earlier
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: patched in version 3.6.5.2