JetFormBuilder before 3.6.5.2 lets unauthenticated visitors run arbitrary shortcodes through its 'status' parameter. Update to version 3.6.5.2 or later.
Affected component: JetFormBuilder — Dynamic Blocks Form Builder (plugin)
Fixed in: 3.6.5.2
PowerSEC coverage: PowerSEC detects the affected versions on every plan, and has since September 28, 2026. No PowerSEC firewall rule blocks this attack. Update to 3.6.5.2 or later to remove the vulnerability.
Full advisory, including detection steps and remediation: https://powersec.io/vulnerability/cve-2026-19859