JetFormBuilder WordPress 插件在 3.6.5.2 版本之前,未在将某个请求参数作为消息内容渲染前对其进行清理(sanitize),这使得未认证用户能够在任何显示表单的页面上执行站点上已注册的任意短代码(shortcodes)。由于转义(escaping)是在后续的短代码展开(shortcode-expansion)步骤之前而非之后应用,因此该转义可以被绕过。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | JetFormBuilder | < 3.6.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | JetFormBuilder | 0 ~ 3.6.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80437 | 4.8 MEDIUM | Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Re |
| CVE-2026-80439 | 4.8 MEDIUM | Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execut |
| CVE-2026-19862 | 4.8 MEDIUM | JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action |
| CVE-2026-85038 | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati | |
| CVE-2026-84219 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| CVE-2026-75793 | SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login | |
| CVE-2026-18480 | SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover | |
| CVE-2026-84028 | Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin | |
| CVE-2026-13159 | Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation |
No comments yet