PT-2025-51376 · WordPress · Jetformbuilder

Tri Firdyanto

·

Published

2025-12-16

·

Updated

2025-12-17

·

CVE-2025-11991

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JetFormBuilder versions up to and including 3.5.3
Description The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress has a flaw that allows unauthorized modification of data. A missing capability check on the run callback function permits unauthenticated attackers to generate forms using AI, potentially exhausting the site's AI usage limits.
Recommendations Update to version 3.5.4 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11991

Affected Products

Jetformbuilder