CVE-2025-11991
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-11991 is a Missing Authorization vulnerability in the JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress, affecting all versions up to and including 3.5.3. The flaw allows unauthenticated attackers to invoke the run_callback function without any capability check, enabling them to trigger AI-powered form generation and exhaust the site's AI usage quota. It was published on December 16, 2025, with Wordfence credited as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing capability check (CWE-862) on the run_callback function within the plugin's AI REST API endpoint, specifically in modules/ai/rest-api/endpoints/generate-form-endpoint.php. Because no authentication or authorization is enforced before executing the callback, any unauthenticated network request can trigger the AI form generation feature. The attack vector is network-accessible, requires no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows unauthenticated attackers to generate forms using the site's configured AI service, directly consuming and potentially exhausting the site owner's AI usage limits or API credits. The confidentiality and availability impacts are rated as none, while integrity impact is low — the primary harm is unauthorized resource consumption and potential financial cost to site operators whose AI quotas are depleted. There is no evidence of data exfiltration or remote code execution risk associated with this vulnerability (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-11991 as of the available data. The EPSS score is approximately 0.051%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it straightforward for any attacker to abuse if the AI feature is enabled (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running JetFormBuilder version 3.5.3 or earlier with the AI form generation feature enabled, using tools like WPScan or Shodan.
  2. Locate the vulnerable endpoint: Target the REST API endpoint registered by generate-form-endpoint.php (e.g., a POST endpoint under the JetFormBuilder REST API namespace).
  3. Send unauthenticated request: Craft an HTTP POST request to the vulnerable REST API endpoint invoking run_callback without any authentication headers or nonce, including parameters to trigger AI form generation.
  4. Consume AI credits: The server processes the request and calls the configured AI service on behalf of the site, consuming the site's AI usage quota with each request. Repeated requests can exhaust the quota rapidly (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: Unusual or high-volume unauthenticated POST requests to the JetFormBuilder AI REST API endpoint (e.g., /wp-json/jet-form-builder/*/generate-form or similar) from external IP addresses.
  • Logs: WordPress access logs showing repeated REST API calls to JetFormBuilder AI endpoints without authentication cookies or nonces, particularly from the same or rotating IP addresses.
  • Application: Unexpected depletion of AI API credits or quota alerts from the configured AI service provider (e.g., OpenAI usage spikes not correlated with legitimate site activity).

Mitigation and workarounds

Site administrators should update the JetFormBuilder plugin to version 3.5.4 or later, which introduces the required capability check on the run_callback function. If an immediate update is not possible, disabling the AI form generation feature within the plugin settings can mitigate the risk. Additionally, restricting access to WordPress REST API endpoints via a web application firewall (WAF) rule for unauthenticated requests to JetFormBuilder AI routes provides a temporary workaround (Wordfence).

Community reactions

The vulnerability was disclosed by Wordfence, which serves as the primary source of technical detail and advisory. Coverage has been picked up by aggregators including VulDB, Vulners, CIRCL, and ENISA's EUVD, indicating standard community awareness for a medium-severity WordPress plugin flaw. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability database indexing (ENISA EUVD).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management