Summary
CVE-2026-19859 is an unauthenticated arbitrary shortcode execution vulnerability affecting the JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress. All versions before 3.6.5.2 are affected. The vulnerability is patched in version 3.6.5.2. There is no evidence of active exploitation.
Affected and patched versions
Status | Version Range |
|---|---|
Vulnerable | All versions before 3.6.5.2 |
Patched | 3.6.5.2 and later |
Is my site vulnerable?
To determine if a WordPress site is vulnerable to CVE-2026-19859, site administrators must check the version of the JetFormBuilder — Dynamic Blocks Form Builder plugin currently installed. This vulnerability affects all versions of the plugin up to, but not including, version 3.6.5.2. If a site runs version 3.6.5.2 or a later release, it incorporates the patch for this issue.
Administrators can verify the plugin version through the WordPress administration dashboard. Navigate to the "Plugins" section, then select "Installed Plugins." Locate "JetFormBuilder — Dynamic Blocks Form Builder" in the list. The version number is typically displayed directly beneath the plugin's name.
Alternatively, the version can be checked by accessing the site's file system. Connect via SFTP or cPanel File Manager and navigate to the wp-content/plugins/jetformbuilder/ directory. Open the jetformbuilder.php file (or the main plugin file, usually named after the plugin folder). The plugin version is declared within the file header comments, often near the top, in a line similar to Version: X.Y.Z. Compare the identified version number against the known vulnerable range. If the installed version is 3.6.5.2 or newer, the site is not vulnerable to this specific issue.
What an attacker actually does
The JetFormBuilder plugin processes user-supplied information as message content, which is then displayed on pages that include a JetFormBuilder form. The vulnerability arises from how this message content is handled. The plugin attempts to secure the content by "escaping" characters that could be used for malicious purposes. However, this escaping process occurs before WordPress has a chance to expand any shortcodes embedded within the content. This incorrect order allows an attacker to bypass the security measure.
Specifically, the plugin's sanitize_wysiwyg() function applies sanitization in an incorrect sequence. It first uses wp_kses_post and then wp_specialchars_decode. This sequence allows an attacker to encode malicious shortcode syntax using HTML entities. These entity-encoded payloads survive the initial wp_kses_post sanitization. Later, wp_specialchars_decode decodes these entities, making the shortcodes active and ready for parsing by WordPress's shortcode expansion mechanism.
An unauthenticated attacker can craft a request that injects shortcode syntax into a form message. When a user visits a page displaying a JetFormBuilder form, the plugin renders this compromised message content. Because the shortcodes bypass the intended escaping, they are executed by the WordPress site. This enables the attacker to execute arbitrary shortcodes registered on the site. The impact of such execution is generally limited to the capabilities of the shortcodes themselves, which could include displaying specific site data or altering the content shown on the page. For example, an attacker might trigger a shortcode that reveals internal user email addresses or other data that a legitimate shortcode is designed to access and display.
How to detect a compromise
Detecting a compromise related to CVE-2026-19859 involves observing the effects of arbitrary shortcode execution on your WordPress site. Since the vulnerability allows an attacker to execute shortcodes that display or modify content on pages with JetFormBuilder forms, the primary indicators of compromise would appear on these specific pages.
Site administrators should regularly review pages that incorporate JetFormBuilder forms for any unexpected or altered content. This could manifest as unusual text, images, or data appearing where it should not. For instance, if a shortcode designed to display user information is exploited, internal user email addresses or other sensitive data might become visible on a public-facing form page. Any sudden changes in the appearance or content of these pages, especially without a corresponding update or modification by a legitimate site administrator, warrant investigation.
Reviewing server access logs can also provide indicators. Look for unusual or repetitive requests to URLs that host JetFormBuilder forms, particularly requests containing atypical or lengthy parameters that might represent injected shortcode payloads. Any abnormal request patterns targeting form submission endpoints or pages displaying forms should be scrutinized. WordPress debug logs or general error logs may also contain entries related to failed shortcode executions or unexpected output if an attacker attempts to use malformed or non-existent shortcodes. A thorough review of logs and of the content on affected pages remains the main way to detect it.
How to fix
To address CVE-2026-19859, follow these steps:
Access your WordPress administration dashboard.
Navigate to the "Plugins" section and select "Installed Plugins."
Locate "JetFormBuilder — Dynamic Blocks Form Builder" in the list.
If an update is available, click the "Update Now" link beneath the plugin name.
Ensure the plugin is updated to version 3.6.5.2 or a later version.
Timeline
Date | Event |
|---|---|
2026-09-03 | Public disclosure |
2026-09-06 | NVD record published |
Sources
https://nvd.nist.gov/vuln/detail/CVE-2026-19859
https://www.wordfence.com/threat-intel/vulnerabilities/id/11f367a0-3a1a-474b-8dae-b3b0f942574a
https://wordpress.org/plugins/jetformbuilder/