Advisory

CVE-2026-19859 in JetFormBuilder — Dynamic Blocks Form Build

CVSS 6.5 (CVE record)Published Sep 30, 2026Last verified Oct 7, 2026

JetFormBuilder before 3.6.5.2 lets unauthenticated visitors run arbitrary shortcodes through its 'status' parameter. Update to version 3.6.5.2 or later.

Exploited in the wild
Not reported
Installs not updated
At least 28.64%
Affected and fixed versions
ComponentAffectedFixed in
JetFormBuilder — Dynamic Blocks Form Builder (plugin)before 3.6.5.23.6.5.2
Run a free scan of your site

The free scan checks what is visible from outside your site. It does not log in, and it cannot confirm on its own whether this specific issue is present.

Summary

CVE-2026-19859 is an unauthenticated arbitrary shortcode execution vulnerability affecting the JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress. All versions before 3.6.5.2 are affected. The vulnerability is patched in version 3.6.5.2. There is no evidence of active exploitation.

Affected and patched versions

Status

Version Range

Vulnerable

All versions before 3.6.5.2

Patched

3.6.5.2 and later

Is my site vulnerable?

To determine if a WordPress site is vulnerable to CVE-2026-19859, site administrators must check the version of the JetFormBuilder — Dynamic Blocks Form Builder plugin currently installed. This vulnerability affects all versions of the plugin up to, but not including, version 3.6.5.2. If a site runs version 3.6.5.2 or a later release, it incorporates the patch for this issue.

Administrators can verify the plugin version through the WordPress administration dashboard. Navigate to the "Plugins" section, then select "Installed Plugins." Locate "JetFormBuilder — Dynamic Blocks Form Builder" in the list. The version number is typically displayed directly beneath the plugin's name.

Alternatively, the version can be checked by accessing the site's file system. Connect via SFTP or cPanel File Manager and navigate to the wp-content/plugins/jetformbuilder/ directory. Open the jetformbuilder.php file (or the main plugin file, usually named after the plugin folder). The plugin version is declared within the file header comments, often near the top, in a line similar to Version: X.Y.Z. Compare the identified version number against the known vulnerable range. If the installed version is 3.6.5.2 or newer, the site is not vulnerable to this specific issue.

What an attacker actually does

The JetFormBuilder plugin processes user-supplied information as message content, which is then displayed on pages that include a JetFormBuilder form. The vulnerability arises from how this message content is handled. The plugin attempts to secure the content by "escaping" characters that could be used for malicious purposes. However, this escaping process occurs before WordPress has a chance to expand any shortcodes embedded within the content. This incorrect order allows an attacker to bypass the security measure.

Specifically, the plugin's sanitize_wysiwyg() function applies sanitization in an incorrect sequence. It first uses wp_kses_post and then wp_specialchars_decode. This sequence allows an attacker to encode malicious shortcode syntax using HTML entities. These entity-encoded payloads survive the initial wp_kses_post sanitization. Later, wp_specialchars_decode decodes these entities, making the shortcodes active and ready for parsing by WordPress's shortcode expansion mechanism.

An unauthenticated attacker can craft a request that injects shortcode syntax into a form message. When a user visits a page displaying a JetFormBuilder form, the plugin renders this compromised message content. Because the shortcodes bypass the intended escaping, they are executed by the WordPress site. This enables the attacker to execute arbitrary shortcodes registered on the site. The impact of such execution is generally limited to the capabilities of the shortcodes themselves, which could include displaying specific site data or altering the content shown on the page. For example, an attacker might trigger a shortcode that reveals internal user email addresses or other data that a legitimate shortcode is designed to access and display.

How to detect a compromise

Detecting a compromise related to CVE-2026-19859 involves observing the effects of arbitrary shortcode execution on your WordPress site. Since the vulnerability allows an attacker to execute shortcodes that display or modify content on pages with JetFormBuilder forms, the primary indicators of compromise would appear on these specific pages.

Site administrators should regularly review pages that incorporate JetFormBuilder forms for any unexpected or altered content. This could manifest as unusual text, images, or data appearing where it should not. For instance, if a shortcode designed to display user information is exploited, internal user email addresses or other sensitive data might become visible on a public-facing form page. Any sudden changes in the appearance or content of these pages, especially without a corresponding update or modification by a legitimate site administrator, warrant investigation.

Reviewing server access logs can also provide indicators. Look for unusual or repetitive requests to URLs that host JetFormBuilder forms, particularly requests containing atypical or lengthy parameters that might represent injected shortcode payloads. Any abnormal request patterns targeting form submission endpoints or pages displaying forms should be scrutinized. WordPress debug logs or general error logs may also contain entries related to failed shortcode executions or unexpected output if an attacker attempts to use malformed or non-existent shortcodes. A thorough review of logs and of the content on affected pages remains the main way to detect it.

How to fix

To address CVE-2026-19859, follow these steps:

  1. Access your WordPress administration dashboard.

  2. Navigate to the "Plugins" section and select "Installed Plugins."

  3. Locate "JetFormBuilder — Dynamic Blocks Form Builder" in the list.

  4. If an update is available, click the "Update Now" link beneath the plugin name.

  5. Ensure the plugin is updated to version 3.6.5.2 or a later version.

Timeline

Date

Event

2026-09-03

Public disclosure

2026-09-06

NVD record published

Sources

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19859

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/11f367a0-3a1a-474b-8dae-b3b0f942574a

  • https://wordpress.org/plugins/jetformbuilder/

PowerSEC coverage
PowerSEC detects the affected versions on every plan, and has since September 28, 2026. No PowerSEC firewall rule blocks this attack. Update to 3.6.5.2 or later to remove the vulnerability.
This record contains material that is subject to copyright Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation
Hacked? Talk to us