SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19861

MEDIUM · CVSS 4.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The JetFormBuilder plugin for WordPress prior to version 3.6.5.2 is vulnerable due to inadequate sanitization and escaping of form field values in HTML notification emails, enabling unauthenticated users to inject arbitrary HTML. This could lead to potential phishing attacks or other malicious activities, as the injected content may be rendered in email clients. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-19861
Severity
MEDIUM
CVSS
4.7
EPSS
0.17%
WordPress

Original NVD Description

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.