All verified exploits

CVE-2026-4373 Unauthenticated Arbitrary File Read via Media Field Path Traversal

Deterministic high WordPress Added cve-verified-cve-2026-4373

Detects WordPress installs running the JetFormBuilder plugin at version 3.5.6.2 or earlier. The Media Field preset handler (set_from_array) accepts arbitrary file paths in the JSON payload without validation. An unauthenticated attacker can submit a form with a crafted preset pointing to sensitive files like wp-config.php. When the Send Email action fires with attachment enabled, the targeted file is exfiltrated as an email attachment.

Related WordPress exploits

Is your app exploitable through CVE-2026-4373?

Scan your domain free