Detects WordPress installs running the JetFormBuilder plugin at version 3.5.6.2 or earlier. The Media Field preset handler (set_from_array) accepts arbitrary file paths in the JSON payload without validation. An unauthenticated attacker can submit a form with a crafted preset pointing to sensitive files like wp-config.php. When the Send Email action fires with attachment enabled, the targeted file is exfiltrated as an email attachment.
Is your app exploitable through CVE-2026-4373?
Scan your domain free