CVE-2026-19862CWE-93

CVE-2026-19862

Medium · published September 6, 2026

CVSS v3.1
4.8
EPSS
In the wild
Unconfirmed
What it is

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.

The record
Technical detail
CVSS v3.1
4.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-93 · Improper Neutralization of CRLF Sequences ('CRLF Injection')
Published
2026-09-06T14:17Z
References (1)
Timeline
  • 06 SEP 09:36Z
    JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action
    cvelistv5