Impact
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field‑validation callback. The blocklist used by the plugin omits a file‑deletion function, which allows a user who can manage forms to configure a callback that invokes deletion of arbitrary files on the server when the form is submitted. This flaw is an instance of CWE-73, whereby insufficient validation of user input permits improper use of functions leading to unintended side effects. The result is permanent removal of server files without authentication, threatening the integrity and availability of the application.
Affected Systems
All installations of JetFormBuilder — Dynamic Blocks Form Builder for WordPress with a version before 3.6.5.3 are affected. Releases from 3.5.6.2 through 3.6.5.2, as well as any intermediate builds below 3.6.5.3, are susceptible. Versions 3.6.5.3 and later are expected to contain the fix.
Risk and Exploitability
The vulnerability can be exploited by any user who has the privilege to create or edit a form with custom validation callbacks, a capability typically granted to form‑management role users. Because the callback executes at form submission over HTTP, the attack vector is remote and does not require prior authentication beyond form‑management rights. The EPSS score of less than 1% indicates a low probability of exploitation, and the CVSS score of 5.5 denotes moderate severity, primarily impacting integrity and availability. The flaw is currently not listed in the CISA KEV catalog.
OpenCVE Enrichment