
Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates administrator accounts.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-12793
JetFormBuilder 3.6.2 - jetmonsters
I am @abraxas_null. Loopback lab. The client is CVE-2026-12793-Abraxas-Labs.py.
The advisory named a field. _jet_engine_booking_form_id is a POST field, not HTTP action=. set_form_id only absint()s. get_blocks_by_post parses any post. A regular post with the right blocks and _jf_actions register-user administrator is enough. The live router hook is not the source default jet_form_builder_submit=submit. Patched in 3.6.2.1.
| CVE | CVE-2026-12793 · CVE.org |
| CWE | CWE-269 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | JetFormBuilder - Dynamic Blocks Form Builder |
| Affected | all versions through 3.6.2 (inclusive) |
| Patched | 3.6.2.1 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Unauthenticated POST / with the live hook pair, that post id, and login/email/password. JSON status: success plus a numeric user_id. That user is an administrator. Creating the user is the proof.
Wordfence named _jet_engine_booking_form_id. I read set_form_id, then get_blocks_by_post, then the action handler. The option table rewrites the router pair on first load.
Discover the pair like a visitor: GET the public REST document for the carrier post. POST / with method=ajax, the live hook pair, and the form id. Small JSON, tens of bytes. If you are still reading a DOCTYPE, you are still lost.
Wrong turns: jet_form_builder_submit=submit returns ~80k theme HTML; REST /jet-form-builder/v1/validate-field is the wrong door on 3.6.2; fighting nonce (load_nonce=hide, use_csrf=false on the fixture); a subscriber because _jf_actions user_role was not administrator (seed miss, not a patch); submitting a real jet-form-builder CPT id (the product working).
Port 8088. JetFormBuilder 3.6.2. Carrier post slug jfb-lab-carrier (post, not jet-form-builder) with hook pair printed in REST.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-12793-Abraxas-Labs.py
Witness: JSON {"user_id":N,"status":"success"} and /wp/v2/users/<id> is administrator. Theme HTML is not it.
Ways to lose without learning anything:
/ 200, ~80k HTML, default hookUpdate JetFormBuilder to 3.6.2.1 or newer. Re-run CVE-2026-12793-Abraxas-Labs.py against the patched build: the administrator user_id must not appear.
www.wordfence.com/threat-intel/vulnerabilities/id/a61b2ecc-d4e1-4e71-9187-ddc3d3616a29?source=cve
Plugin directory: jetformbuilder
Trac browser: plugins.trac.wordpress.org/jetformbuilder
SVN tags: plugins.svn.wordpress.org/jetformbuilder
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.