Description
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.
Published: 2026-09-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetFormBuilder, the Dynamic Blocks Form Builder WordPress plugin, had a flaw where the content from a WYSIWYG form field was inserted into notification emails without proper sanitization. As a result, unauthenticated users could submit arbitrary HTML that would be delivered to administrators or other recipients. The injected markup is rendered in the email regardless of its form, but whether any script within the markup is executed depends on the recipient’s mail client.

Affected Systems

All installations of JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin older than version 3.6.5.2 are vulnerable. The issue applies to any site that loads a pre‑3.6.5.2 instance of the plugin, independent of other configuration.

Risk and Exploitability

The vulnerability can be exploited by submitting any form containing malicious HTML; no authentication is required. Because EPSS information is not available and the flaw is not listed in the CISA KEV catalog, the current exploitation likelihood appears low. Nevertheless, the injected content could be used for phishing or other malicious activity if a recipient’s mail client renders or executes the code. The CVSS score is not specified in the advisory, but the nature of stored XSS indicates a potentially high impact if exploitation succeeds.

Generated by OpenCVE AI on September 5, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JetFormBuilder to version 3.6.5.2 or later.
  • If an upgrade is not possible, restrict form submissions to authenticated users and ensure that the WYSIWYG field is sanitized before it is stored or emailed.
  • Configure the plugin to send plain‑text notification emails, disabling HTML rendering for all outbound messages.

Generated by OpenCVE AI on September 5, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.
Title JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:04.674Z

Reserved: 2026-08-14T10:00:59.401Z

Link: CVE-2026-19861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:11.563

Modified: 2026-09-05T07:17:11.563

Link: CVE-2026-19861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T08:00:06Z

Weaknesses

No weakness.