
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4373 is an absolute path traversal vulnerability (CWE-36) in the JetFormBuilder plugin for WordPress, allowing unauthenticated attackers to read arbitrary local files by exfiltrating them as email attachments. It affects all versions of JetFormBuilder up to and including 3.5.6.2, developed by Crocoblock/JetMonsters. The vulnerability was published on March 21, 2026, and was discovered and reported through Wordfence. It carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, ENISA EUVD).
The root cause lies in two compounding flaws within the JetFormBuilder plugin. First, the Uploaded_File::set_from_array method accepts user-supplied file paths from the Media Field preset JSON payload without validating that the provided path is confined to the WordPress uploads directory. Second, the File_Tools::is_same_file method performs an insufficient same-file check that only compares file basenames rather than full paths, allowing an attacker to bypass the intended restriction. An unauthenticated attacker can exploit this by submitting a crafted form request to any WordPress site where a JetFormBuilder form is configured with both a Media Field and a Send Email action with file attachment enabled — causing the server to attach and send an arbitrary local file to an attacker-controlled email address (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated remote attackers to read arbitrary files from the server's filesystem, including sensitive configuration files such as wp-config.php (containing database credentials), /etc/passwd, private keys, or other sensitive data accessible to the web server process. The confidentiality impact is rated High, with no direct integrity or availability impact. Exposure of database credentials or authentication secrets could enable further compromise, including full site takeover or lateral movement within the hosting environment (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.00137 (low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, exploitation requires no authentication and low complexity, making it accessible to a wide range of threat actors if a suitable form configuration is present on the target site (Wordfence, Feedly).
../../../../wp-config.php or /etc/passwd) instead of a legitimate upload path.Uploaded_File::set_from_array method processes the attacker-supplied path without validating it against the uploads directory.File_Tools::is_same_file method only compares basenames, so a traversal path with a matching basename (if needed) bypasses the check.../, ../../, or absolute paths like /etc/ or /var/www/) in Media Field JSON parameters.wp-config.php, passwd) sent to external or unusual recipient addresses.Users should update the JetFormBuilder plugin to version 3.5.7 or later, which addresses the path traversal vulnerability via the changeset available in the WordPress plugin repository. The patch enforces proper validation that file paths belong to the WordPress uploads directory and improves the same-file comparison logic. As a temporary workaround, administrators can disable any forms that use both a Media Field and a Send Email action with file attachments until the plugin is updated (WordPress Trac Changeset, Wordfence).
Wordfence included CVE-2026-4373 in their weekly WordPress vulnerability report for the week of March 16–22, 2026, highlighting it as a notable unauthenticated file read issue (Wordfence Blog). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). Security community accounts on Mastodon and Twitter/X (via RedPacketSecurity) shared alerts about the CVE shortly after disclosure, and the vulnerability was noted on threat intelligence platforms including offseq.com and infinitsec.net (Mastodon).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."