Junglewise Threat Intelligence

CVE-2026-84817: JetFormBuilder unauthenticated cross-site scripting (XSS)

CVE-2026-84817 · Severity: high · CVSS 7.1 · Published 2026-09-08

Executive brief

JetFormBuilder is a WordPress plugin used to create and manage web forms on websites. An unauthenticated attacker can inject malicious scripts into affected sites that steal visitor data, hijack user accounts, or redirect users to phishing pages. The vulnerability affects all versions up to 3.6.5.1 and requires user interaction to exploit, but can be delivered at scale through mass-exploit campaigns.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability in JetFormBuilder versions ≤ 3.6.5.1. The plugin fails to properly sanitize and validate user input, allowing attackers to inject arbitrary JavaScript code that executes in the context of a victim's browser. The vulnerability requires unauthenticated access but may require user interaction (such as clicking a malicious link or visiting a crafted page) for successful exploitation. An attacker can steal session cookies, credentials, or perform actions on behalf of the victim. The issue has been patched in version 3.6.5.2 or later.

Affected products

  • Crocoblock JetFormBuilder 3.6.5.1 and earlier

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: patched in version 3.6.5.2

References

Related threats