CVE-2026-12793 is an improper privilege-management vulnerability in the JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress through version 3.6.2. The plugin does not verify that a submitted form ID identifies a legitimate JetFormBuilder form before parsing the referenced WordPress post content as a form schema. This processing can invoke an Advanced Validation server-side callback, enabling an unauthenticated attacker to cause creation of a new administrator-level WordPress account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains one standalone Python 3 exploit, a README advisory/lab guide, and a minimal .gitignore. It is not a framework module. The exploit is deliberately constrained to a localhost WordPress lab at 127.0.0.1:8088 rather than accepting an arbitrary target. It first requests a public REST representation of the jfb-lab-carrier post, extracts the post ID plus randomized JetFormBuilder request-router key/value markers, and then sends a URL-encoded POST to the site root. The POST supplies that router pair, method=ajax, the carrier post ID in _jet_engine_booking_form_id, and fixed credentials. The intended vulnerable behavior in JetFormBuilder through 3.6.2 is that the plugin only integer-validates the submitted form ID, parses blocks from an arbitrary post as a form definition, and executes its configured register_user action. A successful response contains status=success and user_id, serving as the exploit witness. The README documents the WordPress/JetFormBuilder call chain, the required crafted carrier post, affected and patched versions, and notes a related Advanced Validation server-side callback path; however, the executable code performs privilege escalation through administrator account creation rather than implementing a command shell or callback payload.
The repository contains a README and a single 36 KB Python 3 program, poc.py. It is a standalone unified scanner and exploit for the claimed JetFormBuilder vulnerability, not a Metasploit/Nuclei module. The script supports single-target and threaded target-list operation, configurable timeouts/proxies/crawl paths, manual form metadata overrides, JSONL results, and separate check, exploit, and registration-fallback modes. It normalizes target URLs, fingerprints JetFormBuilder through its plugin files, crawls common site paths for JetFormBuilder form metadata, and uses discovered form identifiers, nonce/router data, and JetFormBuilder submission parameters to attempt an unauthenticated overwrite of WordPress wp_user_roles. It supplies a comprehensive administrator capability list for the selected role, defaulting to subscriber. With provided low-privilege credentials, it then logs in as the newly privileged user, uploads and activates a generated PHP plugin, and uses its cmd parameter to execute an operator-selected command. The generated plugin is a persistent command web shell rather than a benign validation payload. A fallback path attempts unauthenticated user registration through a discovered register-action form. No fixed target host, IP address, or external command-and-control infrastructure is embedded; all network requests are directed to operator-supplied targets.
This is a small standalone Python repository containing a functional scanner and exploit for CVE-2026-12793 in the Crocoblock JetFormBuilder WordPress plugin. The repository consists of README.md, the executable poc.py, and requirements.txt; poc.py is the only code file and depends on requests and urllib3. It is not part of a recognized exploitation framework. The tool normalizes supplied targets, fingerprints JetFormBuilder by requesting its public plugin readme and, as a fallback, its main PHP file, and compares a parsed Stable tag against 3.6.2. It crawls a configurable set of public paths for JetFormBuilder markers and form metadata, supports single-target and multithreaded list-based operation, proxying, custom timeouts, JSONL reporting, and candidate reuse. In exploit mode, it sends a crafted JetFormBuilder AJAX submission referencing a chosen form through _jet_engine_booking_form_id and related referer/post-ID fields. The intended effect is to cause a Register User action to execute and create a supplied or randomly generated account. The resulting account's privilege is controlled by the vulnerable target form configuration; administrator-level takeover is possible only where that form assigns an administrator or similarly elevated role. Optional verification tests the account at the target's WordPress login endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated privilege-escalation vulnerability in the JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin through version 3.6.2. Insufficient validation of submitted form IDs allows an attacker to cause referenced post content to be parsed as a form schema and invoke an Advanced Validation server-side callback, enabling creation of an administrator-level account.
A critical unauthenticated privilege-escalation vulnerability in the JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin through version 3.6.2. An attacker can submit a form ID for a non-JetFormBuilder post, causing the plugin to parse attacker-controlled referenced content as a form schema and execute an Advanced Validation server-side callback, enabling creation of an administrator-level account.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.