Sceawere

Vulnerability Detail

CVE-2026-97342UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JetFormBuilder Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
jetmonsters
Product
JetFormBuilder — Dynamic Blocks Form Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is submitted via the unauthenticated wp_ajax_nopriv_jet_form_builder_submit endpoint, stored verbatim into post meta through the Insert/Update Post action, and later rendered unescaped by the Select Field block template when the get_from_db option generator copies raw meta values into option value attributes and label content.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:05.317Z",
  "pubdate": "2026-10-02T08:17:05.317Z",
  "executiveSummary": "The JetFormBuilder plugin for WordPress, in all versions up to and including 3.6.5.4, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThe vulnerability stems from improper input sanitization and output escaping within the plugin's 'choice' Post Meta handling logic.\nAn unauthenticated attacker can exploit this flaw by submitting malicious JavaScript payloads via the 'wp_ajax_nopriv_jet_form_builder_submit' endpoint.\nThese payloads are stored directly within the database as post meta and subsequently executed in the browser context of any user who views the affected form pages.\nSuccessful exploitation allows for the execution of arbitrary scripts, potentially leading to unauthorized actions, session hijacking, or redirection of administrative or visitor traffic.\nGiven that the exploitation occurs via an unauthenticated AJAX action, the attack surface is exposed to the public internet, posing a significant security risk to sites utilizing the affected versions of the plugin.",
  "technicalDetails": "The root cause of this vulnerability is the lack of strict input sanitization during the insertion or update of post meta data when processed through the 'wp_ajax_nopriv_jet_form_builder_submit' endpoint.\nWhen a user submits a form, the plugin processes the 'choice' field and stores the provided data directly into the database as post meta associated with the created or updated post.\nThe vulnerability is further exacerbated by the failure of the Select Field block template to perform adequate output escaping when rendering these stored values.\nSpecifically, the component responsible for the 'get_from_db' option generator retrieves the raw, unvalidated strings from the database and inserts them directly into the HTML 'value' attributes and label content within the rendered form output.\nThe attack flow begins when an unauthenticated attacker sends a crafted POST request to the 'wp_ajax_nopriv_jet_form_builder_submit' endpoint containing a malicious payload—typically JavaScript wrapped in HTML tags—within the 'choice' meta parameter.\nSince the endpoint permits unauthenticated access, the attacker does not require any prior session or administrative privileges to inject the payload.\nOnce stored, the payload remains persistent within the WordPress database. Every time a user interacts with a page utilizing the vulnerable Select Field block, the plugin fetches the tainted meta value and reflects it into the DOM unescaped.\nBecause the payload is rendered in the context of the WordPress site, it inherits the application's domain privileges, enabling the execution of arbitrary scripts under the origin of the vulnerable site.\nPost-exploitation impact includes the potential for attackers to steal session cookies, perform unauthorized actions on behalf of authenticated administrators, or modify the visual content of the page to facilitate further phishing or social engineering attacks against the site's users."
}
CVE-2026-97342: JetFormBuilder Stored XSS Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere