Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-12793 — Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates administrator accounts. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-12793
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-12793

CVE-2026-12793

Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates administrator accounts.

3222h 2m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Abraxas Labs - CVE-2026-12793

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-12793

CVE-2026-12793

JetFormBuilder 3.6.2 - jetmonsters

I am @abraxas_null. Loopback lab. The client is CVE-2026-12793-Abraxas-Labs.py.

The advisory named a field. _jet_engine_booking_form_id is a POST field, not HTTP action=. set_form_id only absint()s. get_blocks_by_post parses any post. A regular post with the right blocks and _jf_actions register-user administrator is enough. The live router hook is not the source default jet_form_builder_submit=submit. Patched in 3.6.2.1.

CVECVE-2026-12793 · CVE.org
CWECWE-269
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductJetFormBuilder - Dynamic Blocks Form Builder
Affectedall versions through 3.6.2 (inclusive)
Patched3.6.2.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated POST / with the live hook pair, that post id, and login/email/password. JSON status: success plus a numeric user_id. That user is an administrator. Creating the user is the proof.


How I found it

Wordfence named _jet_engine_booking_form_id. I read set_form_id, then get_blocks_by_post, then the action handler. The option table rewrites the router pair on first load.

Discover the pair like a visitor: GET the public REST document for the carrier post. POST / with method=ajax, the live hook pair, and the form id. Small JSON, tens of bytes. If you are still reading a DOCTYPE, you are still lost.

Wrong turns: jet_form_builder_submit=submit returns ~80k theme HTML; REST /jet-form-builder/v1/validate-field is the wrong door on 3.6.2; fighting nonce (load_nonce=hide, use_csrf=false on the fixture); a subscriber because _jf_actions user_role was not administrator (seed miss, not a patch); submitting a real jet-form-builder CPT id (the product working).


The lab

Port 8088. JetFormBuilder 3.6.2. Carrier post slug jfb-lab-carrier (post, not jet-form-builder) with hook pair printed in REST.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-12793-Abraxas-Labs.py

Witness: JSON {"user_id":N,"status":"success"} and /wp/v2/users/<id> is administrator. Theme HTML is not it.

Ways to lose without learning anything:

  • POST / 200, ~80k HTML, default hook
  • REST validate-field Invalid form ID
  • subscriber instead of administrator
  • reverse shell

The fix

Update JetFormBuilder to 3.6.2.1 or newer. Re-run CVE-2026-12793-Abraxas-Labs.py against the patched build: the administrator user_id must not appear.


References

  • CVE-2026-12793 · NVD

  • CVE-2026-12793 · CVE.org

  • plugins.trac.wordpress.org/changeset/3575346/jetformbuilder

  • www.wordfence.com/threat-intel/vulnerabilities/id/a61b2ecc-d4e1-4e71-9187-ddc3d3616a29?source=cve

  • github.com/advisories/GHSA-579w-q4cr-j8hc

  • nvd.nist.gov/vuln/detail/CVE-2026-12793

  • Plugin directory: jetformbuilder

  • Trac browser: plugins.trac.wordpress.org/jetformbuilder

  • SVN tags: plugins.svn.wordpress.org/jetformbuilder

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool