MEDIUM 6.5 NVD

CVE-2026-19859

The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users

The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.

References

Published: 2026-09-06 · Source: NVD · Feed updated: 2026-09-06
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-09-06 via NVD.
vulnfeed aggregates 10006 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.