Web appOpen in Telegram

PostCVE-2026-12793 – JetFormBuilder WordPress Plugin 🆘

17 September 2026
R
Root Access Club
Photo
click to show
CVE-2026-12793 – JetFormBuilder WordPress Plugin 🆘 Critical vulnerability (CVSS 9.8) ⚠️ Affects versions ≤ 3.6.2 Unauthenticated privilege escalation Fixed in version 3.6.2.1 and later ✅ Attack Flow : 1⃣ Detect JetFormBuilder + version ≤ 3.6.2 (readme.txt) 2⃣ Discover form ID from public pages (data-form-id, /register/, etc.) 4⃣ POST to referer page with ?jet_form_builder_submit=submit&method=ajax 4⃣ Register User action runs → new WP user created If you're using this plugin, update immediately ‼️ GitHub ⛓‍💥 @RootAccessClub
2 · 157 ·

Nearby in the feed

RRoot Access ClubClaude Red 🌪 Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant Covers aRRoot Access ClubXSS Labs🔬 An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based
this message
RRoot Access ClubOWASP Amass 🔎 An open source framework for network mapping and attack surface discovery • Subdomain & DNS enumeration • OSINT-based asset discovery • InfrastrucRRoot Access ClubLegion — Automated Network Pentesting 🛡️ Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumera
RRoot Access ClubRoot Access Club@RootAccessClub · channel
272subscribers152average post reach
Venue feed Open in Telegram

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count