THREAT OPS › Threat News › [NVD] CVE-2026-19862 (MEDIUM 4.8) — The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hi
[NVD] CVE-2026-19862 (MEDIUM 4.8) — The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hi
CVE-2026-19862 CVSS: 4.8 MEDIUM Published: 2026-09-06T10:17:14.563
The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation r
Indicators of compromise
- CVE-2026-19862cve
- 3.6.5.2ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19862