CVE-2026-102391: WordPress JetFormBuilder plugin <= 3.6.5.4 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
Affected Software
1 affected component
JetFormBuilder<=3.6.5.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetFormBuilder - Dynamic Blocks Form Builderto a version that resolves this vulnerability.Fixed in 3.6.6
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What versions are affected?
JetFormBuilder versions 3.6.5.4 and earlier are affected.
2
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account; however, exploitation requires user interaction.
3
What impact can successful exploitation have?
Successful XSS exploitation may affect confidentiality, integrity, and availability at a low level. The CVSS vector also indicates scope may change, meaning effects can extend beyond the vulnerable component.