Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-12793: JetFormBuilder lets anyone create admin accounts
CVE-2026-12793 · published 1 day ago
Summary
The JetFormBuilder form plugin for WordPress can be tricked into giving a stranger full admin rights. An attacker can send a specially crafted request that creates a new admin user without logging in. Update the plugin to the latest version or remove it, and review user accounts for unexpected administrators.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jetmonsters | jetformbuilder — dynamic blocks form builder | <= 3.6.2 |
Original advisory text
JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-269Improper Privilege Management
Timeline
Published16 Sep 2026
Updated16 Sep 2026
First seen16 Sep 2026
Track software like this
Free during beta