Sploitus Critical Privilege Escalation Vulnerability in JetFormBuilder Plugin
Article Content
- •CVE-2026-12793 allows unauthenticated users to escalate privileges.
- •Affected versions include all JetFormBuilder releases up to 3.6.2.
- •Public proof-of-concept code is available, increasing exploitation risk.
The JetFormBuilder plugin for WordPress is vulnerable to a privilege escalation flaw (CVE-2026-12793) affecting all versions up to 3.6.2. The vulnerability allows unauthenticated attackers to create administrator-level accounts by exploiting improper validation of form IDs. Attackers can send crafted AJAX requests to trigger the 'Register User' action, leading to potential full site takeover if forms are misconfigured. A proof-of-concept exploit has been publicly released, raising the urgency for site administrators to secure their installations. The vulnerability was disclosed on September 16, 2026, and is currently unpatched. Users of the JetFormBuilder plugin are strongly advised to assess their configurations and apply necessary mitigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-12793 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…