CVE-2022-4997: JetFormBuilder Stripe Gateway < 1.1.0 - Unauthenticated Blind SQLi via Payment Token
Published Sep 23, 2026
·Updated
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
Affected Software
1 affected component
Crocoblock JetFormBuilder Stripe Gateway<1.1.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue can be exploited by unauthenticated users. No authenticated WordPress account is required.
2
What does an attacker need to supply?
An attacker needs to provide a crafted payment token that reaches the vulnerable SQL statement. The payment token is not sanitised or escaped before use.
3
What data could be exposed?
An attacker may be able to extract arbitrary data from the WordPress database, including password hashes.
4
Which plugin versions are affected?
Versions of Crocoblock JetFormBuilder Stripe Gateway before 1.1.0 are affected.