JetFormBuilder is vulnerable to Privilege Escalation
98
Critical Risk
set_form_id() takes _jet_engine_booking_form_id without checking that the ID is a published jet-form-builder post. The handler then parses that post's content as form schema and runs Advanced Validation server-side callbacks, which can invoke wp_insert_user. An unauthenticated attacker can point the parameter at attacker-controlled post content and create a new administrator. The fix accepts only valid JetFormBuilder form posts and blocks user-mutation callbacks in SSR validation.
You are affected if you are using a version that falls within the vulnerable range.
JetFormBuilder is vulnerable to Privilege Escalation in versions 0.0.1 - 3.6.2.
Upgrade the JetFormBuilder library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.