Impact
JetFormBuilder, the Dynamic Blocks Form Builder WordPress plugin, had a flaw where the content from a WYSIWYG form field was inserted into notification emails without proper sanitization. As a result, unauthenticated users could submit arbitrary HTML that would be delivered to administrators or other recipients. The injected markup is rendered in the email regardless of its form, but whether any script within the markup is executed depends on the recipient’s mail client.
Affected Systems
All installations of JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin older than version 3.6.5.2 are vulnerable. The issue applies to any site that loads a pre‑3.6.5.2 instance of the plugin, independent of other configuration.
Risk and Exploitability
The vulnerability can be exploited by submitting any form containing malicious HTML; no authentication is required. Because EPSS information is not available and the flaw is not listed in the CISA KEV catalog, the current exploitation likelihood appears low. Nevertheless, the injected content could be used for phishing or other malicious activity if a recipient’s mail client renders or executes the code. The CVSS score is not specified in the advisory, but the nature of stored XSS indicates a potentially high impact if exploitation succeeds.
OpenCVE Enrichment