Help/security
security

CVE-2026-19859 in JetFormBuilder — Dynamic Blocks Form Build

Updated October 7, 2026 36 views

JetFormBuilder before 3.6.5.2 lets unauthenticated visitors run arbitrary shortcodes through its 'status' parameter. Update to version 3.6.5.2 or later.

Affected component: JetFormBuilder — Dynamic Blocks Form Builder (plugin)
Fixed in: 3.6.5.2
PowerSEC coverage: PowerSEC detects the affected versions on every plan, and has since September 28, 2026. No PowerSEC firewall rule blocks this attack. Update to 3.6.5.2 or later to remove the vulnerability.

Full advisory, including detection steps and remediation: https://powersec.io/vulnerability/cve-2026-19859

Couldn't find what you're looking for?

Browse more articles or reach out to our support team.

Browse all articles Email support
Hacked? Talk to us
CVE-2026-19859 in JetFormBuilder — Dynamic Blocks Form Build