JetFormBuilder — Dynamic Blocks Form Builder vulnerability

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.

Published 5 Sep 2026Updated 5 Sep 20261 sources
CVSS 0.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.