WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-13459 — JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13459 JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.3.1 Missing Authorization Medium 5.3 < 3.6.3.1 3.6.3.1 2026-07-01

CVE-2026-13459

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve every distinct value stored under any arbitrary wp_postmeta key on the site — including WooCommerce billing PII such as _billing_email, _billing_phone, and _billing_address fields, order totals, attachment paths, and any third-party plugin credentials or tokens stored in post meta — provided at least one published JetFormBuilder form with a get_from_db generator field exists on the site. Exploitation requires that the target site has at least one published jet-form-builder post containing a field whose generator_function is set to get_from_db; an attacker must supply a matching form ID, field name, and generator ID in the request, but all of these can be discovered by browsing the site's public forms.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.