THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19861 — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivere

[NVD] CVE-2026-19861 — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivere

mednvdPublished 2026-09-05

CVE-2026-19861 CVSS: None Published: 2026-09-05T07:17:11.563

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injecte

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19861