Impact
Unauthenticated Cross Site Scripting in the JetFormBuilder plugin allows arbitrary code execution within the context of the affected website. An attacker can inject malicious scripts through form fields that are not properly sanitized, enabling session hijacking, defacement, or theft of sensitive data. The flaw pertains to CWE-79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
JetMonsters JetFormBuilder – Dynamic Blocks Form Builder plugin, all versions 3.6.5.4 and earlier are susceptible. WordPress sites that use the plugin for form creation or management are directly impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity that can be exploited without requiring authentication. While the EPSS score is not available, the absence of public exploits does not reduce the risk, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is likely exploitation of any exposed form page on the site, enabling remote script injection. Given the potential for widespread impact, timely remediation is recommended.
OpenCVE Enrichment