Summary
CVE-2026-28140 is an unauthenticated broken access control (missing authorization) vulnerability in the JetFormBuilder WordPress plugin. It affects all versions up to and including 3.6.4.1 and is rated High severity (CVSS 7.5), allowing remote attackers to reach functionality that should be restricted without any authentication.
Technical details
- Root cause: Missing authorization (CWE-862) — the plugin fails to properly enforce access controls on certain functionality.
- Trigger conditions: No authentication and no user interaction are required to exploit the flaw.
- Attack vector: Network — the weakness is reachable remotely over HTTP/HTTPS against an exposed WordPress site running the plugin.
- Impact: Integrity impact rated High; confidentiality and availability are not impacted per the published CVSS metrics.
Affected software
- JetFormBuilder WordPress plugin versions ≤ 3.6.4.1
- Fixed in version 3.6.4.2
Severity
- CVSS v3.1 base score: 7.5 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Mitigation and recommended actions
- Immediate: Update the JetFormBuilder plugin to version 3.6.4.2 or later.
- If no patch can be applied: Restrict network access to affected WordPress sites and place a web application firewall in front of the application to filter unauthenticated requests to the plugin until the update is deployed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/plugins/jetformbuilder/

