Sceawere

Vulnerability Detail

CVE-2026-103912UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JetFormBuilder Reflected DOM XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
2h ago
Vendor
jetmonsters
Product
JetFormBuilder — Dynamic Blocks Form Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '<attacker-chosen query var name matching the preset's query_var setting>' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on pages embedding a form that has a text field configured with a query_var Dynamic Preset and a data-jfb-macro or JFB_FIELD:: macro reference targeting that field, both of which are standard, documented plugin features.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-10-10T06:16:38.447Z",
  "pubdate": "2026-10-10T06:16:38.447Z",
  "executiveSummary": "The JetFormBuilder plugin for WordPress is susceptible to a Reflected DOM-Based Cross-Site Scripting (XSS) vulnerability. This security flaw exists in versions 3.6.6 and earlier.\nThe vulnerability arises from improper sanitization and escaping of input parameters that are processed by the plugin's Dynamic Preset functionality.\nAn unauthenticated attacker can execute arbitrary malicious JavaScript within the victim's browser context by crafting a specifically formatted URL.\nExploitation requires the attacker to trick a legitimate user into clicking a crafted link while visiting a page that embeds a JetFormBuilder form configured with a specific 'query_var' Dynamic Preset and a 'data-jfb-macro' or 'JFB_FIELD::' reference.\nSuccessful exploitation may lead to session hijacking, unauthorized actions performed on behalf of the user, or the exfiltration of sensitive information.\nThe risk is categorized as high due to the potential for unauthorized client-side code execution without requiring prior authentication.",
  "technicalDetails": "The root cause of this vulnerability is the failure to properly sanitize and escape input values derived from URL query parameters. Specifically, the JetFormBuilder plugin allows form fields to be populated via 'Dynamic Presets'. When a form field is configured to utilize the 'query_var' setting, the plugin reads values directly from the HTTP request parameters.\nThe vulnerability manifests when the application embeds these unsanitized values into the Document Object Model (DOM) via client-side scripts. The mechanism is triggered when a page contains a form field configured with a 'query_var' Dynamic Preset, combined with a 'data-jfb-macro' or 'JFB_FIELD::' macro reference. These features, which are documented parts of the plugin, enable the dynamic injection of form values based on the query string.\nThe attack flow begins when an attacker identifies a target WordPress site using JetFormBuilder. The attacker constructs a malicious URL that includes a parameter name matching the site's configured 'query_var'. By setting the value of this parameter to a crafted JavaScript payload (e.g., <script>alert(document.cookie)</script>), the attacker forces the client-side JavaScript to process this input.\nWhen a user navigates to the attacker-supplied URL, the vulnerable script retrieves the malicious input from the URL parameters. Because the application fails to perform adequate output escaping before rendering this data into the DOM, the browser interprets the injected string as executable code rather than plain text. This executes the script in the context of the user's session.\nThe impact of this DOM-based XSS is significant, as it occurs entirely within the client's browser. Once executed, the malicious payload can access session cookies, bypass Same-Origin Policy (SOP) protections within the context of the origin, perform unauthorized administrative actions, or redirect users to malicious domains. Since the vulnerability is reflected, it requires social engineering to bait a victim into clicking the link, but it does not require the attacker to have administrative privileges or account access, making it highly accessible for unauthenticated exploitation across all versions up to and including 3.6.6."
}
CVE-2026-103912: JetFormBuilder Reflected DOM XSS (MEDIUM Severity, CVSS: 4.7) | Sceawere