CVE-2022-4997 PUBLISHED

JetFormBuilder Stripe Gateway < 1.1.0 - Unauthenticated Blind SQLi via Payment Token

Assigner: WPScan
Reserved: 18.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.

Product Status

Vendor Unknown
Product jet-form-builder-stripe-gateway
Versions Default: unaffected
  • affected from 0 to 1.1.0 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE