{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ajetformbuilderdynamic_blocks_form_builder/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jetformbuilder:dynamic_blocks_form_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-97342"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JetFormBuilder — Dynamic Blocks Form Builder (\u003c= 3.6.5.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["JetFormBuilder"],"content_html":"\u003cp\u003eThe JetFormBuilder - Dynamic Blocks Form Builder plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-97342. The flaw exists in all versions up to and including 3.6.5.4. It stems from insufficient input sanitization and output escaping when handling the 'choice' Post Meta field during the Insert/Update Post action.\u003c/p\u003e\n\u003cp\u003eUnauthenticated attackers can exploit this by sending a crafted request to the \u003ccode\u003ewp_ajax_nopriv_jet_form_builder_submit\u003c/code\u003e endpoint. The malicious payload is stored verbatim in the WordPress post meta database. When a user interacts with a page containing the 'Select Field' block, the plugin renders the stored raw meta values as option attributes and label content, leading to the execution of the injected script in the context of the user's browser. This vulnerability poses a significant risk for session hijacking and unauthorized administrative actions if an administrator views the compromised page.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing a page where the malicious form meta is rendered. This can lead to session token theft, the execution of unauthorized actions within the WordPress dashboard, or credential harvesting, impacting all organizations utilizing versions 3.6.5.4 or earlier of the JetFormBuilder plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by updating the JetFormBuilder - Dynamic Blocks Form Builder plugin to a version greater than 3.6.5.4.\u003c/li\u003e\n\u003cli\u003eAudit WordPress site logs for anomalous requests to the \u003ccode\u003ewp_ajax_nopriv_jet_form_builder_submit\u003c/code\u003e endpoint that include script tags or unusual characters.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to detect and block incoming HTTP requests targeting the \u003ccode\u003ejet_form_builder_submit\u003c/code\u003e action that contain XSS vectors (e.g., \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e, \u003ccode\u003eonerror\u003c/code\u003e, \u003ccode\u003eonload\u003c/code\u003e).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T08:24:46Z","date_published":"2026-10-02T08:24:46Z","id":"https://feed.craftedsignal.io/briefs/2026-10-02-jetformbuilder-xss/","summary":"An unauthenticated stored XSS vulnerability in the JetFormBuilder WordPress plugin allows attackers to inject arbitrary web scripts via the 'choice' Post Meta field.","title":"Stored XSS in JetFormBuilder WordPress Plugin (CVE-2026-97342)","url":"https://feed.craftedsignal.io/briefs/2026-10-02-jetformbuilder-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:jetformbuilder:dynamic_blocks_form_builder:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}