{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/jetformbuilder/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jetformbuilder:dynamic_blocks_form_builder:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-12793"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=0C977A49-52F9-5070-AD85-782B6DDFFD63\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Dynamic Blocks Form Builder (\u003c= 3.6.2)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["JetFormBuilder"],"content_html":"\u003cp\u003eThe JetFormBuilder - Dynamic Blocks Form Builder plugin for WordPress is affected by a critical privilege escalation vulnerability, assigned CVE-2026-12793. The vulnerability exists in versions up to and including 3.6.2. The security flaw stems from a lack of server-side validation concerning submitted form IDs. Specifically, the plugin fails to verify if a provided form ID is legitimate before parsing the referenced post's content as a form schema. This oversight enables the execution of an Advanced Validation server-side callback using attacker-controlled input. An unauthenticated attacker can exploit this mechanism to facilitate the creation of an administrative-level user account on the WordPress site. Given the plugin's functionality, this flaw represents a significant risk to site integrity and control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the affected WordPress instance. Attackers can create unauthorized administrator accounts, leading to complete site compromise, data exfiltration, and the deployment of further malicious persistence mechanisms. This vulnerability affects all WordPress installations utilizing the JetFormBuilder plugin version 3.6.2 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the JetFormBuilder - Dynamic Blocks Form Builder plugin to the latest version immediately to remediate CVE-2026-12793.\u003c/li\u003e\n\u003cli\u003eAudit existing WordPress user accounts for suspicious administrative privileges created after the discovery of this vulnerability.\u003c/li\u003e\n\u003cli\u003eRestrict access to WordPress administrative endpoints and plugin configuration interfaces to authorized networks where possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T16:56:06Z","date_published":"2026-09-16T05:46:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jetformbuilder-privesc/","summary":"An unauthenticated privilege escalation vulnerability (CVE-2026-12793) in the JetFormBuilder plugin allows attackers to register arbitrary administrator accounts via improper server-side validation.","title":"Privilege Escalation in JetFormBuilder Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-jetformbuilder-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - JetFormBuilder","version":"https://jsonfeed.org/version/1.1"}