CVE-2026-4373General

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs to the WordPress uploads directory. Combined with an insufficient same-file check in 'File_Tools::is_same_file' that only compares basenames, this makes it possible for unauthenticated attackers to exfiltrate arbitrary local files as email attachments by submitting a crafted form request when the form is configured with a Media Field and a Send Email action with file attachment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-36

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-21); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-21: 3Mentions · 2026-03-22: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-21: 203-2103-22
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-213
Disclosure1General1Patch1
2026-03-221
General1
Full discourse4 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4373 - jetmonsters - JetFormBuilder — Dynamic Blocks Form Builder - https://www.redpacketsecurity.com/cve-alert-cve-2026-4373-jetmonsters-jetformbuilder-dynamic-blocks-form-builder/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4373 #jetmonsters #jetformbuilder-dynamic-blocks-form-builder

    Post summary

    The post simply announces a CVE alert for JetFormBuilder without providing PoC, exploitation info, or remediation details.

    00000112
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4373 WordPress JetFormBuilder Plugin Unauthenticated Arbitrary ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4373 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet merely references CVE-2026-4373 affecting the JetFormBuilder plugin, with no evidence of PoC, exploit code, active exploitation, patch, or detailed technical information.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4373 The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploa… https://www.cve.org/CVERecord?id=CVE-2026-4373

    Post summary

    The JetFormBuilder WordPress plugin is vulnerable to path‑traversal leading to arbitrary file reads; no PoC, exploit code, or active exploitation is reported, nor is a patch mentioned.

    0000056
    56.8K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-4373: JetFormBuilder for WordPress lets unauthenticated users read any file via crafted form uploads. Upgrade to 3.5.6.3 now to keep data safe! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-4373 #WordPress #infosec #AppSec

    Post summary

    CVE-2026-4373 permits unauthenticated file reads in JetFormBuilder via crafted uploads; the advisory urges users to upgrade to version 3.5.6.3 to address the flaw.

    0000036
    55 followersView on X

Explore more