CVE-2026-103912
Received Received - Intake

Reflected DOM-Based XSS in JetFormBuilder WordPress Plugin

Vulnerability report for CVE-2026-103912, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '<attacker-chosen query var name matching the preset's query_var setting>' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on pages embedding a form that has a text field configured with a query_var Dynamic Preset and a data-jfb-macro or JFB_FIELD:: macro reference targeting that field, both of which are standard, documented plugin features.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jetmonsters JetFormBuilder β€” Dynamic Blocks Form Builder 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Reflected DOM-Based Cross-Site Scripting (XSS) issue in the JetFormBuilder plugin for WordPress. It occurs due to insufficient input sanitization and output escaping in the plugin's handling of a specific query variable. Attackers can exploit this by injecting malicious scripts into pages that embed forms with certain configurations, tricking users into clicking a link to execute the script.

Detection Guidance

This vulnerability is specific to WordPress sites using the JetFormBuilder plugin. Detection involves checking plugin versions and inspecting forms for vulnerable configurations. No direct network/system commands are provided in the context. Review WordPress admin panels for JetFormBuilder versions up to 3.6.6 and examine forms with text fields using Dynamic Presets with query_var settings.

Impact Analysis

Unauthenticated attackers could inject arbitrary web scripts into pages you visit if you use the vulnerable plugin. This could lead to theft of sensitive data, session hijacking, or redirection to malicious sites. Users might unknowingly execute these scripts by clicking a crafted link, potentially compromising their accounts or personal information.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles or HIPAA's security requirements. If exploited, it may result in data breaches, triggering compliance violations, legal penalties, or reputational damage for organizations handling sensitive user information.

Mitigation Strategies

Update the JetFormBuilder plugin to the latest version beyond 3.6.6 to patch the vulnerability. Remove any forms with text fields configured with a query_var Dynamic Preset and data-jfb-macro or JFB_FIELD:: macro references until updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103912. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart