Back

MEDIUM

JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action

Published Sep 6, 2026

Description

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 6, 2026
Updated Sep 6, 2026
Reserved Aug 14, 2026
CISA Vulnrichment
Updated Sep 6, 2026
NVD
Status Deferred
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Sep 6, 2026
Updated Sep 6, 2026
Exploited since n/a
EUVD-2026-72090