Stored XSS in JetFormBuilder WordPress Plugin (CVE-2026-97342)
An unauthenticated stored XSS vulnerability in the JetFormBuilder WordPress plugin allows attackers to inject arbitrary web scripts via the 'choice' Post Meta field.
CVE search metadata
CVE search record: CVE-2026-97342. Severity: high. CVSS: 7.2. KEV: no. Product: JetFormBuilder — Dynamic Blocks Form Builder (<= 3.6.5.4). Brief: Stored XSS in JetFormBuilder WordPress Plugin (CVE-2026-97342). Brief link: https://feed.craftedsignal.io/briefs/2026-10-02-jetformbuilder-xss/
The JetFormBuilder - Dynamic Blocks Form Builder plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-97342. The flaw exists in all versions up to and including 3.6.5.4. It stems from insufficient input sanitization and output escaping when handling the 'choice' Post Meta field during the Insert/Update Post action.
Unauthenticated attackers can exploit this by sending a crafted request to the wp_ajax_nopriv_jet_form_builder_submit endpoint. The malicious payload is stored verbatim in the WordPress post meta database. When a user interacts with a page containing the 'Select Field' block, the plugin renders the stored raw meta values as option attributes and label content, leading to the execution of the injected script in the context of the user's browser. This vulnerability poses a significant risk for session hijacking and unauthorized administrative actions if an administrator views the compromised page.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing a page where the malicious form meta is rendered. This can lead to session token theft, the execution of unauthorized actions within the WordPress dashboard, or credential harvesting, impacting all organizations utilizing versions 3.6.5.4 or earlier of the JetFormBuilder plugin.
Recommendation
- Patch immediately by updating the JetFormBuilder - Dynamic Blocks Form Builder plugin to a version greater than 3.6.5.4.
- Audit WordPress site logs for anomalous requests to the
wp_ajax_nopriv_jet_form_builder_submitendpoint that include script tags or unusual characters. - Deploy web application firewall (WAF) rules to detect and block incoming HTTP requests targeting the
jet_form_builder_submitaction that contain XSS vectors (e.g.,<script>,onerror,onload).
Immediate actions
Upgrade JetFormBuilder plugin to latest version
Mitigations
Implement WAF blocking for script-like strings on the admin-ajax endpoint
CVE-2026-97342
Detection coverage 1
Detects CVE-2026-97342 Exploitation - XSS Injection via Form Submission
highDetects unauthenticated POST requests to the JetFormBuilder submission endpoint containing common XSS payloads in parameters.
Detection queries are available on the platform. Get full rules →