MEDIUM

CVE-2026-54196

2026-06-17 CVSS v3.1
CVSS
6.8

Description

Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation.

This issue affects JetFormBuilder: from n/a through 3.6.1.

Summary dbcve.org

This is a privilege escalation vulnerability in the JetFormBuilder WordPress plugin affecting versions 3.6.1 and below. The vulnerability allows users with the Subscriber role to elevate their privileges, likely through improper capability checks in the plugin's form handling or administrative functions.

Mitigation

Update JetFormBuilder to the latest version once available. If a patch is not available, consider restricting subscriber registration or implementing additional access controls at the web application firewall level.

Weakness (CWE)

CWE-266 Incorrect Privilege Assignment

EPSS Score

0.24%
Probability of exploitation in next 30 days
15th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE