The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve every distinct value stored under any arbitrary wppostmeta key on the site — including WooCommerce billing PII such as billingemail, billingphone, and billingaddress fields, order totals, attachment paths, and any third-party plugin credentials or tokens stored in post meta — provided at least one published JetFormBuilder form with a getfromdb generator field exists on the site. Exploitation requires that the target site has at least one published jet-form-builder post containing a field whose generatorfunction is set to getfromdb; an attacker must supply a matching form ID, field name, and generator ID in the request, but all of these can be discovered by browsing the site's public forms.