Impact
The JetFormBuilder plugin for WordPress fails to verify that a submitted 'form ID' belongs to a legitimate JetFormBuilder form before parsing the referenced content as form schema. This flaw permits unauthenticated users to trigger an Advanced Validation server‑side callback that creates a new administrator‑level account. The weakness is a classic privilege escalation problem (CWE‑269).
Affected Systems
Any WordPress site using JetFormBuilder versions 3.6.2 or older, which includes all releases up to and including 3.6.2 from the JetMonsters JetFormBuilder product line.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. The EPSS score of less than 1% suggests low current exploitation probability, and it is not yet listed in CISA KEV. Nonetheless, because the flaw permits creation of a privileged account with no authentication, the risk to site confidentiality and integrity is absolute. The likely attack vector involves sending a crafted HTTP request containing an arbitrary '_jet_engine_booking_form_id' parameter to the plugin’s endpoint, which can be performed by anyone with network access to the WordPress installation.
OpenCVE Enrichment