Description
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Published: 2026-08-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Broken Access Control in JetFormBuilder plugin versions up to 3.6.4.1 allows an attacker to perform actions normally restricted to privileged users, such as creating, editing, or deleting forms. This can result in unauthorized data exposure, alteration, or loss, and potentially serve as a foothold to further compromise the WordPress site. The vulnerability is categorized as CWE-862, indicating improper enforcement of access control policies.

Affected Systems

The affected product is JetMonsters JetFormBuilder plugin for WordPress. Versions up to 3.6.4.1 are impacted. No other products or versions are listed in the current advisories.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity. While the EPSS score is not available, the absence of a listing in CISA KEV suggests that exploitation is currently not widespread, yet the high CVSS indicates significant potential damage if discovered and exploited. The attack vector is inferred to be unauthenticated access to the WordPress site, taking advantage of the plugin's lack of proper authorization checks.

Generated by OpenCVE AI on August 6, 2026 at 15:27 UTC.

Remediation

Vendor Solution

Update the WordPress JetFormBuilder Plugin to the latest available version (at least 3.6.4.2).


OpenCVE Recommended Actions

  • Update the JetFormBuilder plugin to version 3.6.4.2 or later to eliminate the vulnerability.
  • Restrict direct access to the plugin’s administration URLs by configuring web server rules or firewall rules so that only authenticated and authorized users can reach them.
  • Review and adjust form creation and editing permissions in WordPress to ensure that only trusted roles have the necessary capabilities, and audit existing forms for any unauthorized entries.

Generated by OpenCVE AI on August 6, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetmonsters
Jetmonsters jetformbuilder
Wordpress
Wordpress wordpress
Vendors & Products Jetmonsters
Jetmonsters jetformbuilder
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Title WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Jetmonsters Jetformbuilder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:10.517Z

Reserved: 2026-02-25T12:14:18.579Z

Link: CVE-2026-28140

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses