CVE-2026-19860
5.5 MEDIUMPublished 2026-09-19 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
Weaknesses
CWE-73
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-15307PoC
- HIGHCVE-2026-18806
- HIGHCVE-2026-53940PoC
- UNSCOREDCVE-2026-54584PoC
- HIGHCVE-2026-60009PoC
- UNSCOREDCVE-2026-61647PoC
- CRITICALCVE-2026-90817
- LOWCVE-2026-93987PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.