CVE-2026-4373 PUBLISHED

JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field

Assigner: Wordfence
Reserved: 18.03.2026 Published: 21.03.2026 Updated: 21.03.2026

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs to the WordPress uploads directory. Combined with an insufficient same-file check in 'File_Tools::is_same_file' that only compares basenames, this makes it possible for unauthenticated attackers to exfiltrate arbitrary local files as email attachments by submitting a crafted form request when the form is configured with a Media Field and a Send Email action with file attachment.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor jetmonsters
Product JetFormBuilder — Dynamic Blocks Form Builder
Versions Default: unaffected
  • affected from * to 3.5.6.2 (incl.)

Credits

  • daroo finder

References

Problem Types

  • CWE-36 Absolute Path Traversal CWE