WP Clinic
Log in Sign up

CVE · Critical

CVE-2026-32525 — JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32525 JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.6.2 Improper Control of Generation of Code ('Code Injection') Critical 9.9 < 3.5.6.2 3.5.6.2 2026-03-23

CVE-2026-32525

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.6.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.