rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-97342

The JetFormBuilder Dynamic Blocks Form Builder plugin for WordPress is vulnerable to stored cross‑site scripting via the 'choice' post meta

Overview

The JetFormBuilder Dynamic Blocks Form Builder plugin for WordPress is vulnerable to stored cross‑site scripting via the 'choice' post meta field. Unauthenticated users can submit malicious scripts through the wp_ajax_nopriv_jet_form_builder_submit endpoint, which are stored and later rendered unescaped in form pages. This flaw allows attackers to execute arbitrary code in the browsers of anyone who views the affected pages.

Description

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is submitted via the unauthenticated wp_ajax_nopriv_jet_form_builder_submit endpoint, stored verbatim into post meta through the Insert/Update Post action, and later rendered unescaped by the Select Field block template when the get_from_db option generator copies raw meta values into option value attributes and label content.

Impact

Stored XSS can compromise the confidentiality of user data, alter page content (integrity), and potentially disrupt site functionality (availability). Site administrators and visitors are at risk, as any user who loads a page containing the injected payload will execute the malicious script.

Remediation

Update JetFormBuilder to the latest version (>=3.6.5.5) or any release that removes the vulnerability. If an update is not immediately possible, disable the wp_ajax_nopriv_jet_form_builder_submit endpoint for unauthenticated users or restrict it to authenticated roles. Additionally, ensure that all form input is properly sanitized and output is escaped, and consider using a web application firewall to block XSS payloads.

Risk context

The vulnerability is rated high with a CVSS v3 score of 7.2 and an EPSS of 0.00241, indicating a low probability of exploitation but significant impact if triggered. Defenders should treat this as a moderate‑to‑high priority patching task.

Affected products

  • JetFormBuilder
  • WordPress

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00241

XSS WordPress JetFormBuilder Stored XSS wp_ajax Unauthenticated Plugin Vulnerability

← All CVEs