CVE · Medium

CVE-2026-13459 — JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13459 JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.3.1 Missing Authorization Medium 5.3 < 3.6.3.1 3.6.3.1 2026-07-01

CVE-2026-13459

A vulnerability exists in the JetFormBuilder plugin for WordPress, affecting versions up to 3.6.3. The issue arises from inadequate authorization checks, allowing attackers to access sensitive information, such as user data and plugin credentials, without proper authentication. This can be exploited by targeting a site with at least one published form containing a specific type of field, and providing the necessary information in a request.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.