Critical severity9.8NVD Advisory· Published Sep 16, 2026
CVE-2026-12793
CVE-2026-12793
Description
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.
Affected products
2<=3.6.2+ 1 more
- (no CPE)range: <=3.6.2
- (no CPE)range: <=3.6.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.