CVE-2022-4997
JetFormBuilder Stripe Gateway < 1.1.0 - Unauthenticated Blind SQLi via Payment Token
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
| Vendor | unknown |
| Product | jet-form-builder-stripe-gateway |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown jet-form-builder-stripe-gateway
Be the first to know when new unknown vulnerabilities affecting unknown jet-form-builder-stripe-gateway are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / jet-form-builder-stripe-gateway
0 < 1.1.0
References
Credits
Jakub Herman WPScan