
Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates administrator accounts.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-12793
JetFormBuilder — Dynamic Blocks Form Builder 3.6.2 — jetmonsters
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.
| CVE | CVE-2026-12793 · CVE.org |
| CWE | CWE-269 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | JetFormBuilder — Dynamic Blocks Form Builder |
| Affected | all versions through 3.6.2 (inclusive) |
| Patched | 3.6.2.1 and later |
| Auth | none (see source map) |
| Lab | 127.0.0.1 only · vendor/client disclosure pack, not a scanner |
The advisory names _jet_engine_booking_form_id and Advanced Validation. That POST field is Form_Handler::$form_key. The router hook is NOT the source default jet_form_builder_submit=submit; it is the randomized gfb_request_args_key/value. PHP method names are not HTTP action=. REST validate-field is the wrong route on 3.6.2 (validate_form_post_type already runs).
POST/GET /?rest_route=/wp/v2/posts&slug=jfb-lab-carrier -> id plus JFB_HOOK_KEY / JFB_HOOK_VAL (options-tab gfb_request_args_*)POST / REQUEST[hook_key]=hook_val method=ajax (NOT jet_form_builder_submit=submit)Form_Request_Router::listen (includes/request/request-router.php) uses Form_Handler::$hook_key/$hook_valForm_Handler::process_form -> setup_form -> set_form_id absint only (includes/form-handler.php:150-154, 183-200, 240)send_form: Action_Handler::set_form_id -> set_form_actions from _jf_actions of that post (includes/actions/action-handler.php:71-117)Request_Handler::set_form_data -> Block_Helper::get_blocks_by_post parse_blocks any post (includes/blocks/block-helper.php:186-201; includes/request/request-handler.php:30-33)block-parsers Module::init_request apply those blocks (modules/block-parsers/module.php:101-119)Default_Process_Event runs Register_User_Action::do_action wp_insert_user with settings.user_role (modules/actions-v2/register-user/register-user-action.php:66-215)SSR path (same schema): Server_Side_Rule::validate_custom call_user_func if the field rule value is a PHP function not in NOT_ALLOWED (modules/validation/advanced-rules/server-side-rule.php:187-194)POST JSON contains status success and a numeric user_id. Follow-up GET /?rest_route=/wp/v2/users/<user_id> or a later list that includes login poc_12793 with role administrator. Unique login poc_12793 is the marker — not hello-world HTML.
Do this first: Update JetFormBuilder — Dynamic Blocks Form Builder to 3.6.2.1 or newer.
Verify after upgrade
CVE-2026-12793-Abraxas-Labs.py against the patched build: the mapped witness must not appear.If you cannot update immediately
Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.
python3 CVE-2026-12793-Abraxas-Labs.py
Success is the witness above in the response body. Generic 200 HTML is not it.
Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.
cd lab
docker compose up --force-recreate
Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.