CVE-2026-19861
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 05, 2026
Vendor
unknown
Description
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.