MEDIUM
JetFormBuilder
CVE published 2026-09-05
CVE-2026-19861
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. This vulnerability can lead to potential HTML injection in email notifications, impact [truncated]