🔐 CVE Alert

CVE-2026-19860

UNKNOWN 0.0

JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.

Vendor unknown
Product jetformbuilder — dynamic blocks form builder
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown jetformbuilder — dynamic blocks form builder

Be the first to know when new unknown vulnerabilities affecting unknown jetformbuilder — dynamic blocks form builder are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / JetFormBuilder — Dynamic Blocks Form Builder
3.5.6.2 < 3.6.5.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/d73d8d27-6dad-4a7f-bf51-f5fc18ebc81f/

Credits

Sai Praneeth Koti WPScan