1 vulnerability across 1 product scored HIGH or above on September 16, 2026.
- ๐ HIGH: 1
๐ [HIGH] jetmonsters/jetformbuilder_โ_dynamic_blocks_form_builder
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:jetmonsters:jetformbuilder_dynamic_blocks_form_builder:*:*:*:*:*:*:*:*(< 3.6.3)
JetFormBuilder โ Dynamic Blocks Form Builder by JetMonsters, a WordPress plugin used for building dynamic forms, is affected by one critical vulnerability (CVE-2026-12793, CVSS 9.8). An unauthenticated attacker can exploit a flaw in form ID validation to execute arbitrary server-side callbacks, ultimately creating a new administrator-level user account and fully compromising the WordPress site.
All versions up to and including 3.6.2 are affected, and the vulnerability is considered exploitable. Any organization running JetFormBuilder on WordPress should treat this as an urgent priority. Administrators should update immediately to the patched version available via the WordPress plugin repository and review their sites for any unauthorized administrator accounts that may have been created.
- ๐ CVE-2026-12793 (CVSS 3.1: 9.8)