JetFormBuilder — Dynamic Blocks Form Builder

Information

Software Type Plugin
Software Slug jetformbuilder (view on wordpress.org)
Software Status Active
Software Author jetmonsters
Software Website jetformbuilder.com
Software Downloads 1,944,884
Software Active Installs 80,000
Software Record Last Updated July 19, 2026

12 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter Patched CVE-2026-13459 5.3 Niv Kochan July 1, 2026
JetFormBuilder — Dynamic Blocks Form Builder <= 3.6.0.1 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-54195 7.2 daroo June 16, 2026
JetFormBuilder — Dynamic Blocks Form Builder <= 3.6.1 - Authenticated (Subscriber+) Privilege Escalation Patched CVE-2026-54196 8.8 Jonathan Dersch June 16, 2026
JetFormBuilder — Dynamic Blocks Form Builder <= 3.5.6.1 - Authenticated (Contributor+) Remote Code Execution Patched CVE-2026-32525 8.8 daroo March 23, 2026
JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field Patched CVE-2026-4373 7.5 daroo March 20, 2026
JetFormBuilder <= 3.5.3 - Missing Authorization to Unauthenticated Form Generation Patched CVE-2025-11991 5.3 Tri Firdyanto (Firdy) December 15, 2025
JetFormBuilder <= 3.5.3 - Missing Authorization Patched CVE-2025-64384 5.3 benzdeus November 29, 2025
JetFormBuilder <= 3.5.1.2 - Authenticated (Administrator+) PHP Object Injection Patched CVE-2025-53990 6.6 Que Thanh Tuan - Blue Rock July 16, 2025
JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation Patched CVE-2024-7291 7.2 István Márton August 2, 2024
JetFormBuilder <= 3.1.4 - Unauthenticated Content Injection Patched CVE-2023-48763 5.3 Revan Arifio November 28, 2023
JetFormBuilder <= 3.0.8 - Authenticated (Author+) Privilege Escalation Patched CVE-2023-37866 8.8 Rafie Muhammad July 10, 2023
JetFormBuilder <= 3.0.6 - Cross-Site Request Fogery via 'do_admin_action' Patched CVE-2023-33212 4.3 May 24, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation