PT-2026-54946 · WordPress · Jetformbuilder

·

CVE-2026-13459

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions JetFormBuilder — Dynamic Blocks Form Builder versions prior to 3.6.4
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. This allows unauthenticated attackers to retrieve every distinct value stored under any arbitrary wp postmeta key on the site. This includes WooCommerce billing personally identifiable information (PII) such as billing email, billing phone, and billing address fields, order totals, attachment paths, and third-party plugin credentials or tokens stored in post meta. Exploitation is possible if the site has at least one published JetFormBuilder form with a field where the generator function is set to get from db. The attacker must provide a matching form ID, field name, and generator ID in the request, which can be discovered by browsing public forms.
Recommendations Update to version 3.6.4 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13459

Affected Products

Jetformbuilder