All verified exploits

CVE-2026-32525 Authenticated Remote Code Execution via SSR Validation Callback

Deterministic critical WordPress Added cve-verified-cve-2026-32525

Detects WordPress installs running the JetFormBuilder plugin at version 3.5.6.1 or earlier. The server-side rule validation system passes a user-controlled callback function name to call_user_func() with a trivially bypassable blacklist — the check is case-sensitive and omits critical functions like passthru, proc_open, and eval. A contributor-level user can execute arbitrary PHP functions via the REST API validate-field endpoint, achieving full server compromise.

Related WordPress exploits

Is your app exploitable through CVE-2026-32525?

Scan your domain free