CVE-2026-4373: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4373 is an absolute path traversal vulnerability (CWE-36) in the JetFormBuilder plugin for WordPress, allowing unauthenticated attackers to read arbitrary local files by exfiltrating them as email attachments. It affects all versions of JetFormBuilder up to and including 3.5.6.2, developed by Crocoblock/JetMonsters. The vulnerability was published on March 21, 2026, and was discovered and reported through Wordfence. It carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, ENISA EUVD).

Technical details

The root cause lies in two compounding flaws within the JetFormBuilder plugin. First, the Uploaded_File::set_from_array method accepts user-supplied file paths from the Media Field preset JSON payload without validating that the provided path is confined to the WordPress uploads directory. Second, the File_Tools::is_same_file method performs an insufficient same-file check that only compares file basenames rather than full paths, allowing an attacker to bypass the intended restriction. An unauthenticated attacker can exploit this by submitting a crafted form request to any WordPress site where a JetFormBuilder form is configured with both a Media Field and a Send Email action with file attachment enabled — causing the server to attach and send an arbitrary local file to an attacker-controlled email address (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated remote attackers to read arbitrary files from the server's filesystem, including sensitive configuration files such as wp-config.php (containing database credentials), /etc/passwd, private keys, or other sensitive data accessible to the web server process. The confidentiality impact is rated High, with no direct integrity or availability impact. Exposure of database credentials or authentication secrets could enable further compromise, including full site takeover or lateral movement within the hosting environment (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.00137 (low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, exploitation requires no authentication and low complexity, making it accessible to a wide range of threat actors if a suitable form configuration is present on the target site (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the JetFormBuilder plugin (version ≤ 3.5.6.2) with a publicly accessible form that includes a Media Field and a Send Email action configured to attach uploaded files. Tools like WPScan or Shodan can help identify JetFormBuilder installations.
  2. Craft malicious JSON payload: Prepare a form submission request where the Media Field preset JSON payload contains a user-supplied file path pointing to a sensitive server file (e.g., ../../../../wp-config.php or /etc/passwd) instead of a legitimate upload path.
  3. Submit crafted request: Send the crafted HTTP POST request to the vulnerable form endpoint. The Uploaded_File::set_from_array method processes the attacker-supplied path without validating it against the uploads directory.
  4. Bypass same-file check: The File_Tools::is_same_file method only compares basenames, so a traversal path with a matching basename (if needed) bypasses the check.
  5. Receive exfiltrated file: The Send Email action attaches the resolved arbitrary file and sends it to the configured recipient email. If the attacker controls or can observe the recipient address, they receive the sensitive file contents (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual HTTP POST requests to JetFormBuilder form endpoints containing path traversal sequences (e.g., ../, ../../, or absolute paths like /etc/ or /var/www/) in Media Field JSON parameters.
  • Logs: WordPress or web server access logs showing form submission requests with anomalous file path values in POST body parameters; repeated form submissions from the same IP targeting the same form.
  • Email: Outbound emails generated by the WordPress Send Email action containing unexpected file attachments (e.g., wp-config.php, passwd) sent to external or unusual recipient addresses.
  • File System: No direct file system artifacts are created by this read-only attack, but review of email logs or mail transfer agent (MTA) logs may reveal suspicious attachment filenames.

Mitigation and workarounds

Users should update the JetFormBuilder plugin to version 3.5.7 or later, which addresses the path traversal vulnerability via the changeset available in the WordPress plugin repository. The patch enforces proper validation that file paths belong to the WordPress uploads directory and improves the same-file comparison logic. As a temporary workaround, administrators can disable any forms that use both a Media Field and a Send Email action with file attachments until the plugin is updated (WordPress Trac Changeset, Wordfence).

Community reactions

Wordfence included CVE-2026-4373 in their weekly WordPress vulnerability report for the week of March 16–22, 2026, highlighting it as a notable unauthenticated file read issue (Wordfence Blog). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). Security community accounts on Mastodon and Twitter/X (via RedPacketSecurity) shared alerts about the CVE shortly after disclosure, and the vulnerability was noted on threat intelligence platforms including offseq.com and infinitsec.net (Mastodon).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management