JetFormBuilder WordPress 插件在 3.6.5.2 版本之前,在将表单字段中的地址值添加到邮件头部时,未对换行符进行验证或过滤。这使得未经认证的用户可以注入任意邮件头部,添加隐藏收件人并伪造发件人。利用该漏洞需要站点配置为从表单字段获取邮件中的某个地址。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | JetFormBuilder | < 3.6.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | JetFormBuilder | 0 ~ 3.6.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19859 | 6.5 MEDIUM | JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Para |
| CVE-2026-80437 | 4.8 MEDIUM | Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Re |
| CVE-2026-80439 | 4.8 MEDIUM | Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execut |
| CVE-2026-85038 | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati | |
| CVE-2026-84219 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| CVE-2026-75793 | SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login | |
| CVE-2026-18480 | SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover | |
| CVE-2026-84028 | Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin | |
| CVE-2026-13159 | Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation |
No comments yet