The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Wordfence confirms the JetFormBuilder stored XSS flaw (CVE-2026-97342) affecting versions through 3.6.5.4 with matching CVSS details.

Sourcing
1source

via NVD

NVD · track record
36Stories
100%Verified
1730d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/JetFormBuilder Plugin Hit by Stored XSS Flaw Through Version 3.6.5.4
VERIFIEDBy Xavier Rivera· ·1 min read

JetFormBuilder Plugin Hit by Stored XSS Flaw Through Version 3.6.5.4

The JetFormBuilder WordPress plugin harbors a stored XSS issue through version 3.6.5.4 that permits unauthenticated script injection into post meta, which then executes via Select Field options.

Source:NVD
Post
JetFormBuilder Plugin Hit by Stored XSS Flaw Through Version 3.6.5.4
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

The JetFormBuilder WordPress plugin contains a stored cross-site scripting flaw in versions through 3.6.5.4. Unauthenticated attackers inject scripts via the wp_ajax_nopriv_jet_form_builder_submit endpoint. Data stores unsanitized in post meta and executes on visits due to missing escaping in the Select Field block. The flaw scores 7.2 CVSS and rates high severity.

The JetFormBuilder plugin for WordPress harbors a stored cross-site scripting vulnerability in all editions through version 3.6.5.4.
Scripts can be injected by unauthenticated parties through an open endpoint.
The flaw carries a CVSS score of 7.2. The vector is listed as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N. NVD classifies the issue in the HIGH severity bucket.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Scripts can be injected by unauthenticated parties through an open endpoint. Data arrives at wp_ajax_nopriv_jet_form_builder_submit and gets stored exactly as received into post meta by the Insert/Update Post action.
Escaping failures in the Select Field block template enable execution.
Escaping failures in the Select Field block template enable execution. Raw meta values flow via the get_from_db option generator straight into option value attributes and label content, triggering on any page visit.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
The problem centers on the 'choice' Post Meta route due to missing checks. Wordfence documented the case under identifier 84857045-833f-44fb-ada0-1e0f4eb84a52.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
wordpresssecurityvulnerability
More fromNVD
  • Ninja Forms File Uploads plugin vulnerable to CVSS 8.1 arbitrary file flaw

    Tech · 4h
  • CVE-2026-102878 scores 8.1 in mcp-chrome-bridge through 1.0.31

    Tech · 2d
  • IBM i 7.6 hit by high-severity file ownership vulnerability

    Tech · 2d
More inTech
  • CISA adds Fortinet FortiMail path traversal flaw to KEV catalog

    Tech · 14h
  • Poppy Playtime Spin-Off Escape From Playtime Opens Beta Today

    Tech · 14h
  • Former Tarkov Devs Unveil Concept Art for Rush is Real

    Tech · 21h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Critical CVE-2026-94541 in WPMobile.App Plugin

    The WPMobile.App WordPress plugin is vulnerable to authorization bypass through version 11.82, enabling unauthenticated attackers to steal password-reset URLs when the mail-to-push feature is enabled. The flaw carries a CVSS score of 9.8 and can result in full account takeover for arbitrary users including administrators.

  • Tech· 

    Ninja Forms File Uploads plugin vulnerable to CVSS 8.1 arbitrary file flaw

    Versions of the Ninja Forms - File Uploads plugin through 3.3.34 allow unauthenticated attackers to perform arbitrary file read, write, and deletion by abusing the Amazon S3 upload mechanism, with remote code execution possible when that feature is active.

  • Tech· 

    CVE-2026-102878 scores 8.1 in mcp-chrome-bridge through 1.0.31

    CVE-2026-102878 carries a CVSS score of 8.1 and impacts mcp-chrome-bridge through version 1.0.31 due to a CORS origin validation error. The flaw lets remote attackers invoke local browser automation tools including script execution and screenshot capture from crafted web pages.

  • Tech· 

    Critical Command Injection Flaw in IBM Guardium 12.2

    Version 12.2 of IBM Guardium Data Protection carries the critical CVE-2026-84436 flaw scoring 9.1 on CVSS. Command injection in the certificate export CLI lets a privileged user execute commands as root.

  • Tech· 

    High-Severity MONAI Flaw Lets Local Users Run Code via Poisoned Pickle Cache

    CVE-2026-100841 affects every release of the MONAI medical imaging AI framework through 1.6.0. A local user who can write to a shared cache directory can plant a malicious pickle file that runs code in another user's pipeline. It is rated high severity and no stable fix has shipped.