{"api_version":"1","generated_at":"2026-09-19T07:47:17+00:00","cve":"CVE-2026-19860","urls":{"html":"https://cve.report/CVE-2026-19860","api":"https://cve.report/api/cve/CVE-2026-19860.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-19860","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-19860"},"summary":{"title":"JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback","description":"The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-19 07:16:32","updated_at":"2026-09-19 07:16:32"},"problem_types":["CWE-73 External Control of File Name or Path"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/d73d8d27-6dad-4a7f-bf51-f5fc18ebc81f/","name":"https://wpscan.com/vulnerability/d73d8d27-6dad-4a7f-bf51-f5fc18ebc81f/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19860","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19860","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"JetFormBuilder — Dynamic Blocks Form Builder","version":"affected 3.5.6.2 3.6.5.3 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Sai Praneeth Koti","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"JetFormBuilder — Dynamic Blocks Form Builder","vendor":"Unknown","versions":[{"lessThan":"3.6.5.3","status":"affected","version":"3.5.6.2","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Sai Praneeth Koti"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication."}],"problemTypes":[{"descriptions":[{"description":"CWE-73 External Control of File Name or Path","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-19T06:00:14.409Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/d73d8d27-6dad-4a7f-bf51-f5fc18ebc81f/"}],"source":{"discovery":"EXTERNAL"},"title":"JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-19860","datePublished":"2026-09-19T06:00:14.409Z","dateReserved":"2026-08-14T10:00:56.687Z","dateUpdated":"2026-09-19T06:00:14.409Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-19 07:16:32","lastModifiedDate":"2026-09-19 07:16:32","problem_types":["CWE-73 External Control of File Name or Path"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"19860","Ordinal":"1","Title":"JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletio","CVE":"CVE-2026-19860","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"19860","Ordinal":"1","NoteData":"The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.","Type":"Description","Title":"JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletio"}]}}}