# JetFormBuilder <= 3.6.6 - Unauthenticated Insecure Direct Object Reference to Anonymous Post Update and Trash

- **ID:** WPSEC-2026-0689
- **Plugin:** JetFormBuilder — Dynamic Blocks Form Builder (`jetformbuilder`), https://wordpress.org/plugins/jetformbuilder/
- **Affected versions:** all versions before 3.6.6.1
- **Fixed in:** 3.6.6.1 (Update to 3.6.6.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/jetformbuilder
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0689/

## Description

The JetFormBuilder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the Post ID property of the Insert/Update Post action in all versions up to, and including, 3.6.6, due to the ownership check comparing a post's author to the current user ID, which is 0 for logged-out visitors and therefore matches posts that have no author. This makes it possible for unauthenticated attackers to update or trash anonymously authored posts, such as posts created by earlier anonymous form submissions, by supplying their ID to a form that uses the Insert/Update Post action.

## References

- https://wpsec.com/vuln/WPSEC-2026-0689/
- https://plugins.svn.wordpress.org/jetformbuilder/tags/3.6.6.1/
- https://wordpress.org/plugins/jetformbuilder/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0689/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
