DIRAS TAKE
Urgent: public exploit code exists and the flaw allows unauthenticated admin creation, so treat vulnerable sites as high risk and act immediately to isolate and remediate exposed installations.
What is CVE-2026-12793?
An unauthenticated attacker can create an administrator account on sites using the JetFormBuilder — Dynamic Blocks Form Builder plugin, enabling full site compromise; this is tracked as CVE-2026-12793. The flaw affects JetFormBuilder 3.x — version 3.6.2 and earlier — and occurs because the plugin parses and executes form schema from a referenced post without confirming the post is a JetFormBuilder form. An attacker only needs HTTP access to a vulnerable WordPress site; no login or user interaction is required. The weakness is classified as CWE-269 (Improper Privilege Management).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of jetmonsters JetFormBuilder — Dynamic Blocks Form Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.6.2 and earlier |
Is CVE-2026-12793 being exploited?
Public exploit code is available.
How to fix CVE-2026-12793
- Remove or deactivate the JetFormBuilder plugin on internet-facing sites until a vendor patch is released.
- Restrict access to the WordPress admin and plugin endpoints (use WAF rules, IP allowlists, or HTTP auth).
- Audit existing administrator accounts and revoke or investigate any unknown accounts; rotate credentials and invalidate sessions.
- Monitor logs for suspicious form submissions and the creation of new users; apply vendor guidance and install updates as soon as a fixed version is published.
Frequently asked questions
Is CVE-2026-12793 being actively exploited?
Public exploit code for CVE-2026-12793 is available, which increases the risk of active exploitation against JetFormBuilder instances.
Which JetFormBuilder — Dynamic Blocks Form Builder versions are affected by CVE-2026-12793?
JetFormBuilder versions on the 3.x branch up to and including 3.6.2 are affected by CVE-2026-12793.
Is there a patch for CVE-2026-12793?
No fixed version is listed for CVE-2026-12793; follow the vendor's guidance and apply updates when the vendor releases a patched JetFormBuilder version.
Does CVE-2026-12793 require authentication?
No — CVE-2026-12793 can be exploited without authentication against the JetFormBuilder plugin.
References
- nvd.nist.gov/vuln/detail/CVE-2026-12793
- cve.org/CVERecord?id=CVE-2026-12793
- wordfence.com/threat-intel/vulnerabilities/id/a61b2ecc-d4e1-4e71-9187-ddc3d3616a29?source=cve
- plugins.trac.wordpress.org/changeset/3575346/jetformbuilder
- All jetmonsters CVEs on CVE Radar
- CVEs published in September 2026