<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>JetFormBuilder — Dynamic Blocks Form Builder (&lt;= 3.6.5.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jetformbuilder--dynamic-blocks-form-builder--3.6.5.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:24:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jetformbuilder--dynamic-blocks-form-builder--3.6.5.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in JetFormBuilder WordPress Plugin (CVE-2026-97342)</title><link>https://feed.craftedsignal.io/briefs/2026-10-02-jetformbuilder-xss/</link><pubDate>Fri, 02 Oct 2026 08:24:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-02-jetformbuilder-xss/</guid><description>An unauthenticated stored XSS vulnerability in the JetFormBuilder WordPress plugin allows attackers to inject arbitrary web scripts via the 'choice' Post Meta field.</description><content:encoded><![CDATA[<p>The JetFormBuilder - Dynamic Blocks Form Builder plugin for WordPress is affected by a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-97342. The flaw exists in all versions up to and including 3.6.5.4. It stems from insufficient input sanitization and output escaping when handling the 'choice' Post Meta field during the Insert/Update Post action.</p>
<p>Unauthenticated attackers can exploit this by sending a crafted request to the <code>wp_ajax_nopriv_jet_form_builder_submit</code> endpoint. The malicious payload is stored verbatim in the WordPress post meta database. When a user interacts with a page containing the 'Select Field' block, the plugin renders the stored raw meta values as option attributes and label content, leading to the execution of the injected script in the context of the user's browser. This vulnerability poses a significant risk for session hijacking and unauthorized administrative actions if an administrator views the compromised page.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing a page where the malicious form meta is rendered. This can lead to session token theft, the execution of unauthorized actions within the WordPress dashboard, or credential harvesting, impacting all organizations utilizing versions 3.6.5.4 or earlier of the JetFormBuilder plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by updating the JetFormBuilder - Dynamic Blocks Form Builder plugin to a version greater than 3.6.5.4.</li>
<li>Audit WordPress site logs for anomalous requests to the <code>wp_ajax_nopriv_jet_form_builder_submit</code> endpoint that include script tags or unusual characters.</li>
<li>Deploy web application firewall (WAF) rules to detect and block incoming HTTP requests targeting the <code>jet_form_builder_submit</code> action that contain XSS vectors (e.g., <code>&lt;script&gt;</code>, <code>onerror</code>, <code>onload</code>).</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>xss</category></item></channel></rss>