VYPR

Jetformbuilder

by WordPress

Source repositories

CVEs (13)

  • CVE-2026-32525CriMar 25, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.

  • CVE-2026-28140HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

  • CVE-2025-53990HigJul 16, 2025
    risk 0.47cvss 7.2epss 0.00

    Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Object Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.1.2.

  • CVE-2024-7291HigAug 3, 2024
    risk 0.47cvss 7.2epss 0.01

    The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above…

  • CVE-2023-37866HigMay 17, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.

  • CVE-2026-54195HigJun 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

  • CVE-2026-54196MedJun 17, 2026
    risk 0.44cvss 6.8epss 0.00

    Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

  • CVE-2026-4373HigMar 21, 2026
    risk 0.42cvss 7.5epss 0.00

    The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload…

  • CVE-2025-11991MedDec 16, 2025
    risk 0.34cvss 5.3epss 0.00

    The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated…

  • CVE-2025-64384MedNov 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetFormBuilder: from n/a through <= 3.5.3.

  • CVE-2023-48763MedApr 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.

  • CVE-2023-33212MedMay 28, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.

  • CVE-2026-13459MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…