• PoC PUBLIC

CVE-2026-12793: privilege escalation in jetmonsters JetFormBuilder — Dynamic Blocks Form Builder

An unauthenticated attacker can create an administrator account on sites using the JetFormBuilder — Dynamic Blocks Form Builder plugin, enabling full site compromise; this is tracked as CVE-2026-12793. The flaw affects JetFormBuilder 3.x — version 3.6.2 and earlier — and occurs because the plugin parses and executes form schema from a referenced post without confirming the post is a JetFormBuilder form. An attacker only needs HTTP access to a vulnerable WordPress site; no login or user interaction is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00517
CWE
CWE-269
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists and the flaw allows unauthenticated admin creation, so treat vulnerable sites as high risk and act immediately to isolate and remediate exposed installations.

What is CVE-2026-12793?

An unauthenticated attacker can create an administrator account on sites using the JetFormBuilder — Dynamic Blocks Form Builder plugin, enabling full site compromise; this is tracked as CVE-2026-12793. The flaw affects JetFormBuilder 3.x — version 3.6.2 and earlier — and occurs because the plugin parses and executes form schema from a referenced post without confirming the post is a JetFormBuilder form. An attacker only needs HTTP access to a vulnerable WordPress site; no login or user interaction is required. The weakness is classified as CWE-269 (Improper Privilege Management).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of jetmonsters JetFormBuilder — Dynamic Blocks Form Builder are affected?

BRANCHAFFECTEDFIXED
3.x3.6.2 and earlier

Is CVE-2026-12793 being exploited?

Public exploit code is available.

How to fix CVE-2026-12793

  1. Remove or deactivate the JetFormBuilder plugin on internet-facing sites until a vendor patch is released.
  2. Restrict access to the WordPress admin and plugin endpoints (use WAF rules, IP allowlists, or HTTP auth).
  3. Audit existing administrator accounts and revoke or investigate any unknown accounts; rotate credentials and invalidate sessions.
  4. Monitor logs for suspicious form submissions and the creation of new users; apply vendor guidance and install updates as soon as a fixed version is published.

Frequently asked questions

Is CVE-2026-12793 being actively exploited?

Public exploit code for CVE-2026-12793 is available, which increases the risk of active exploitation against JetFormBuilder instances.

Which JetFormBuilder — Dynamic Blocks Form Builder versions are affected by CVE-2026-12793?

JetFormBuilder versions on the 3.x branch up to and including 3.6.2 are affected by CVE-2026-12793.

Is there a patch for CVE-2026-12793?

No fixed version is listed for CVE-2026-12793; follow the vendor's guidance and apply updates when the vendor releases a patched JetFormBuilder version.

Does CVE-2026-12793 require authentication?

No — CVE-2026-12793 can be exploited without authentication against the JetFormBuilder plugin.

References