# JetFormBuilder <= 3.6.6 - Unauthenticated Missing Authorization to Media Field Value Modification

- **ID:** WPSEC-2026-0690
- **Plugin:** JetFormBuilder — Dynamic Blocks Form Builder (`jetformbuilder`), https://wordpress.org/plugins/jetformbuilder/
- **Affected versions:** all versions before 3.6.6.1
- **Fixed in:** 3.6.6.1 (Update to 3.6.6.1 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/jetformbuilder
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0690/

## Description

The JetFormBuilder plugin for WordPress is vulnerable to Missing Authorization via the Media field in all versions up to, and including, 3.6.6, due to the field's 'user access' capability being checked only when a file is actually uploaded. A submission that carries a value but no file skips the check. This makes it possible for unauthenticated attackers, or users without the configured capability, to write values such as attachment URLs into the post properties and meta keys a restricted Media field is mapped to, on forms that use such a field with the Insert/Update Post action.

## References

- https://wpsec.com/vuln/WPSEC-2026-0690/
- https://plugins.svn.wordpress.org/jetformbuilder/tags/3.6.6.1/
- https://wordpress.org/plugins/jetformbuilder/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0690/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
