PT-2026-54946 · WordPress · Jetformbuilder
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JetFormBuilder — Dynamic Blocks Form Builder versions prior to 3.6.4
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. This allows unauthenticated attackers to retrieve every distinct value stored under any arbitrary
wp postmeta key on the site. This includes WooCommerce billing personally identifiable information (PII) such as billing email, billing phone, and billing address fields, order totals, attachment paths, and third-party plugin credentials or tokens stored in post meta. Exploitation is possible if the site has at least one published JetFormBuilder form with a field where the generator function is set to get from db. The attacker must provide a matching form ID, field name, and generator ID in the request, which can be discovered by browsing public forms.Recommendations
Update to version 3.6.4 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetformbuilder