CyberRota Analysis
AI-GeneratedThe JetFormBuilder plugin for WordPress prior to version 3.6.5.2 is vulnerable due to inadequate sanitization and escaping of form field values in HTML notification emails, enabling unauthenticated users to inject arbitrary HTML. This could lead to potential phishing attacks or other malicious activities, as the injected content may be rendered in email clients. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.