WordPress Plugin Vulnerabilities

JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails

Description

The plugin does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.

Proof of Concept

Affects Plugins

Fixed in 3.6.5.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 2 days ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other