MEDIUM
CVE-2026-54196
CVSS
6.8
Description
Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation.
This issue affects JetFormBuilder: from n/a through 3.6.1.
Summary dbcve.org
This is a privilege escalation vulnerability in the JetFormBuilder WordPress plugin affecting versions 3.6.1 and below. The vulnerability allows users with the Subscriber role to elevate their privileges, likely through improper capability checks in the plugin's form handling or administrative functions.
Mitigation
Update JetFormBuilder to the latest version once available. If a patch is not available, consider restricting subscriber registration or implementing additional access controls at the web application firewall level.
Weakness (CWE)
CWE-266
Incorrect Privilege Assignment
EPSS Score
0.24%
Probability of exploitation in next 30 days
15th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.