Impact
The JetFormBuilder WordPress plugin versions prior to 3.6.5.2 does not sanitize the 'status' request parameter before rendering it as part of a form’s message content. Because escaping is performed after shortcode expansion, a malicious payload can be injected that is later interpreted as a WordPress shortcode. This allows an unauthenticated visitor to execute any shortcode registered on the site, potentially enabling arbitrary code execution, data exfiltration, or site compromise.
Affected Systems
Any WordPress site that has JetFormBuilder installed with a version earlier than 3.6.5.2 and displays a form on a public page is affected, regardless of the underlying operating system or other plugins.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. Attackers do not need to authenticate; the attack vector is an unauthenticated request to any public page that hosts a JetFormBuilder form. Because the flaw permits arbitrary shortcode execution, a skilled attacker could run malicious code, alter content, or steal data.
OpenCVE Enrichment