<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Dynamic Blocks Form Builder (&lt;= 3.6.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dynamic-blocks-form-builder--3.6.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 05:46:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dynamic-blocks-form-builder--3.6.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in JetFormBuilder Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-09-jetformbuilder-privesc/</link><pubDate>Wed, 16 Sep 2026 05:46:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-jetformbuilder-privesc/</guid><description>An unauthenticated privilege escalation vulnerability (CVE-2026-12793) in the JetFormBuilder plugin allows attackers to register arbitrary administrator accounts via improper server-side validation.</description><content:encoded><![CDATA[<p>The JetFormBuilder - Dynamic Blocks Form Builder plugin for WordPress is affected by a critical privilege escalation vulnerability, assigned CVE-2026-12793. The vulnerability exists in versions up to and including 3.6.2. The security flaw stems from a lack of server-side validation concerning submitted form IDs. Specifically, the plugin fails to verify if a provided form ID is legitimate before parsing the referenced post's content as a form schema. This oversight enables the execution of an Advanced Validation server-side callback using attacker-controlled input. An unauthenticated attacker can exploit this mechanism to facilitate the creation of an administrative-level user account on the WordPress site. Given the plugin's functionality, this flaw represents a significant risk to site integrity and control.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative control over the affected WordPress instance. Attackers can create unauthorized administrator accounts, leading to complete site compromise, data exfiltration, and the deployment of further malicious persistence mechanisms. This vulnerability affects all WordPress installations utilizing the JetFormBuilder plugin version 3.6.2 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the JetFormBuilder - Dynamic Blocks Form Builder plugin to the latest version immediately to remediate CVE-2026-12793.</li>
<li>Audit existing WordPress user accounts for suspicious administrative privileges created after the discovery of this vulnerability.</li>
<li>Restrict access to WordPress administrative endpoints and plugin configuration interfaces to authorized networks where possible.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>plugin</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>