
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11991 is a Missing Authorization vulnerability in the JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress, affecting all versions up to and including 3.5.3. The flaw allows unauthenticated attackers to invoke the run_callback function without any capability check, enabling them to trigger AI-powered form generation and exhaust the site's AI usage quota. It was published on December 16, 2025, with Wordfence credited as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the run_callback function within the plugin's AI REST API endpoint, specifically in modules/ai/rest-api/endpoints/generate-form-endpoint.php. Because no authentication or authorization is enforced before executing the callback, any unauthenticated network request can trigger the AI form generation feature. The attack vector is network-accessible, requires no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker (Wordfence, WordPress Plugin Trac).
Successful exploitation allows unauthenticated attackers to generate forms using the site's configured AI service, directly consuming and potentially exhausting the site owner's AI usage limits or API credits. The confidentiality and availability impacts are rated as none, while integrity impact is low — the primary harm is unauthorized resource consumption and potential financial cost to site operators whose AI quotas are depleted. There is no evidence of data exfiltration or remote code execution risk associated with this vulnerability (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-11991 as of the available data. The EPSS score is approximately 0.051%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it straightforward for any attacker to abuse if the AI feature is enabled (Wordfence, ENISA EUVD).
generate-form-endpoint.php (e.g., a POST endpoint under the JetFormBuilder REST API namespace).run_callback without any authentication headers or nonce, including parameters to trigger AI form generation./wp-json/jet-form-builder/*/generate-form or similar) from external IP addresses.Site administrators should update the JetFormBuilder plugin to version 3.5.4 or later, which introduces the required capability check on the run_callback function. If an immediate update is not possible, disabling the AI form generation feature within the plugin settings can mitigate the risk. Additionally, restricting access to WordPress REST API endpoints via a web application firewall (WAF) rule for unauthenticated requests to JetFormBuilder AI routes provides a temporary workaround (Wordfence).
The vulnerability was disclosed by Wordfence, which serves as the primary source of technical detail and advisory. Coverage has been picked up by aggregators including VulDB, Vulners, CIRCL, and ENISA's EUVD, indicating standard community awareness for a medium-severity WordPress plugin flaw. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability database indexing (ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."