Vulnerabilities / JetFormBuilder / WPSEC-2026-0690

JetFormBuilder <= 3.6.6 - Unauthenticated Missing Authorization to Media Field Value Modification

Low 3.7 CWE-862Fixed in 3.6.6.1
ID
WPSEC-2026-0690
Plugin
JetFormBuilder — Dynamic Blocks Form Builder (jetformbuilder)
Affected
all versions before 3.6.6.1
Remediation
Update to 3.6.6.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
JetFormBuilder on WPSec AttackSurface
Fix released
Published

Description

The JetFormBuilder plugin for WordPress is vulnerable to Missing Authorization via the Media field in all versions up to, and including, 3.6.6, due to the field's 'user access' capability being checked only when a file is actually uploaded. A submission that carries a value but no file skips the check. This makes it possible for unauthenticated attackers, or users without the configured capability, to write values such as attachment URLs into the post properties and meta keys a restricted Media field is mapped to, on forms that use such a field with the Insert/Update Post action.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0