CVE-2026-19860
JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.
| Vendor | unknown |
| Product | jetformbuilder — dynamic blocks form builder |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown jetformbuilder — dynamic blocks form builder
Be the first to know when new unknown vulnerabilities affecting unknown jetformbuilder — dynamic blocks form builder are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / JetFormBuilder — Dynamic Blocks Form Builder
3.5.6.2 < 3.6.5.3
References
Credits
Sai Praneeth Koti WPScan