Vulnerabilities / JetFormBuilder / WPSEC-2026-0690
JetFormBuilder <= 3.6.6 - Unauthenticated Missing Authorization to Media Field Value Modification
Low 3.7
CWE-862Fixed in 3.6.6.1
- ID
- WPSEC-2026-0690
- Plugin
- JetFormBuilder — Dynamic Blocks Form Builder (jetformbuilder)
- Affected
- all versions before 3.6.6.1
- Remediation
- Update to 3.6.6.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
- Attack surface
- JetFormBuilder on WPSec AttackSurface
- Fix released
- Published
Description
The JetFormBuilder plugin for WordPress is vulnerable to Missing Authorization via the Media field in all versions up to, and including, 3.6.6, due to the field's 'user access' capability being checked only when a file is actually uploaded. A submission that carries a value but no file skips the check. This makes it possible for unauthenticated attackers, or users without the configured capability, to write values such as attachment URLs into the post properties and meta keys a restricted Media field is mapped to, on forms that use such a field with the Insert/Update Post action.
References
- https://wpsec.com/vuln/WPSEC-2026-0690/
- https://plugins.svn.wordpress.org/jetformbuilder/tags/3.6.6.1/
- https://wordpress.org/plugins/jetformbuilder/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS