Impact
JetFormBuilder, a form builder plugin for WordPress, contains an unauthenticated Cross Site Scripting weakness that permits injection of arbitrary JavaScript code into web pages. The flaw arises when the plugin processes form data without proper sanitization or encoding, allowing an attacker to embed malicious scripts that execute in the context of a victim’s browser. The primary impact is the ability of an attacker to manipulate page content, steal authentication tokens, or carry out phishing attacks against site visitors.
Affected Systems
The vulnerability affects the Crocoblock JetFormBuilder plugin for WordPress version 3.6.5.1 and earlier releases. Users running any of these versions are at risk until they upgrade to a patched release.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated attacker submitting crafted input via a form, as the flaw does not require any special privileges. Given the nature of XSS, any user viewing the vulnerable page could be impacted, making the risk notable for sites with high traffic or sensitive data.
OpenCVE Enrichment