THREAT OPS › Threat News › [NVD] CVE-2026-19861 — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivere
[NVD] CVE-2026-19861 — The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivere
CVE-2026-19861 CVSS: None Published: 2026-09-05T07:17:11.563
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injecte
Indicators of compromise
- CVE-2026-19861cve
- 3.6.5.2ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19861