THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19858 — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, includin

[NVD] CVE-2026-19858 — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, includin

mednvdPublished 2026-09-05

CVE-2026-19858 CVSS: None Published: 2026-09-05T07:17:11.467

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19858