Description
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.
Published: 2026-09-19
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Deletion
Action: Immediate Patch
AI Analysis

Impact

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field‑validation callback. The blocklist used by the plugin omits a file‑deletion function, which allows a user who can manage forms to configure a callback that invokes deletion of arbitrary files on the server when the form is submitted. This flaw is an instance of CWE-73, whereby insufficient validation of user input permits improper use of functions leading to unintended side effects. The result is permanent removal of server files without authentication, threatening the integrity and availability of the application.

Affected Systems

All installations of JetFormBuilder — Dynamic Blocks Form Builder for WordPress with a version before 3.6.5.3 are affected. Releases from 3.5.6.2 through 3.6.5.2, as well as any intermediate builds below 3.6.5.3, are susceptible. Versions 3.6.5.3 and later are expected to contain the fix.

Risk and Exploitability

The vulnerability can be exploited by any user who has the privilege to create or edit a form with custom validation callbacks, a capability typically granted to form‑management role users. Because the callback executes at form submission over HTTP, the attack vector is remote and does not require prior authentication beyond form‑management rights. The EPSS score of less than 1% indicates a low probability of exploitation, and the CVSS score of 5.5 denotes moderate severity, primarily impacting integrity and availability. The flaw is currently not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 00:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JetFormBuilder to version 3.6.5.3 or later to apply the vendor patch.
  • Disable or tightly restrict custom field‑validation callbacks; configure the plugin to reject user‑supplied functions that perform file deletion.
  • If an upgrade is not possible, limit form‑management capabilities to highly trusted administrators and audit form settings.

Generated by OpenCVE AI on September 20, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Jetmonsters
Jetmonsters jetformbuilder — Dynamic Blocks Form Builder
Wordpress-extensions
Wordpress-extensions jetformbuilder
Vendors & Products Jetmonsters
Jetmonsters jetformbuilder — Dynamic Blocks Form Builder
Wordpress-extensions
Wordpress-extensions jetformbuilder

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L'}


Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.
Title JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback
References

Subscriptions

Jetmonsters Jetformbuilder — Dynamic Blocks Form Builder
Wordpress-extensions Jetformbuilder
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:20:41.684Z

Reserved: 2026-08-14T10:00:56.687Z

Link: CVE-2026-19860

cve-icon Vulnrichment

Updated: 2026-09-19T13:13:30.417Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:32.417

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-19860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:42Z

Weaknesses
  • CWE-73

    External Control of File Name or Path