CVE-2026-19862
Received Received - Intake

JetFormBuilder WordPress Plugin Email Header Injection

Vulnerability report for CVE-2026-19862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-06

Last updated on: 2026-09-06

Assigner: WPScan

Description

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-06
Last Modified
2026-09-06
Generated
2026-09-06
AI Q&A
2026-09-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jetformbuilder jetformbuilder to 3.6.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated email header injection in the JetFormBuilder WordPress plugin before version 3.6.5.2. It occurs because the plugin does not validate or strip line breaks from address values submitted via form fields before adding them to email headers. This allows attackers to inject arbitrary email headers, add hidden recipients, and spoof the sender.

Detection Guidance

Check if your JetFormBuilder plugin version is below 3.6.5.2. Inspect form submissions that include email fields for unusual header patterns or additional recipients in email logs.

Impact Analysis

This vulnerability can allow attackers to send emails that appear to come from your domain, add unauthorized recipients to emails, or manipulate email content. If your site uses JetFormBuilder and is configured to take email addresses from form fields, attackers could exploit this to send phishing emails or spam from your domain.

Mitigation Strategies

Update JetFormBuilder to version 3.6.5.2 or later immediately. Disable any form configurations that use user-submitted email addresses for message headers until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart