Skip to main content
QUIETLYTIC
Vulnerability

JetFormBuilder Privilege Escalation (CVE-2026-54196)

CVE-2026-54196 is a CVSS 6.8 privilege escalation in the JetFormBuilder WordPress plugin, per VulnCheck alone.

CVE-2026-54196
Threat Level
MEDIUM
CVSS
6.8
Status
Active Exploitation
Confidence
Medium
Affected Products
JetFormBuilder (up to 3.6.1)

CVE-2026-54196 carries a CVSS 3.1 base score of 6.8 against JetFormBuilder, a WordPress form-building plugin by Crocoblock. NVD classifies it as CWE-266 (Incorrect Privilege Assignment) and states the flaw affects versions through 3.6.1. VulnCheck’s KEV feed reports the CVE as exploited, dated September 16, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-54196 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description for this CVE is brief: “Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation,” affecting versions through 3.6.1. NVD does not name the specific code path or capability check responsible; Patchstack’s vulnerability database entry, cited from NVD’s own reference list, is the only additional public source we currently have, and our source data does not carry deeper mechanism detail from it. The CVSS vector indicates this requires low privileges (PR:L) and high attack complexity (AC:H).

Evidence and confidence

  • Medium confidence — the CVSS 6.8 score, the vector (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N), and the CWE-266 classification, which trace to NVD alone in our current ingestion, with a corroborating listing from Patchstack. The exploitation report traces to VulnCheck KEV alone.
  • Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00236, a 14.8th percentile score as of our ingestion.

No field is in conflict between our two sources.

Why this matters

Privilege escalation flaws in form-building plugins are a meaningful risk on any WordPress site that allows external users to submit forms, since the attack surface starts wherever untrusted input reaches the plugin’s processing logic. The requirement for existing low-level privileges and high attack complexity narrows the practical exploitation window relative to a fully unauthenticated flaw, but any site with open registration or public form submission enabled should still treat this as a priority patch given the confirmed exploitation status.

Frequently Asked Questions

What is CVE-2026-54196? A CVSS 6.8 incorrect privilege assignment vulnerability (CWE-266) in the JetFormBuilder WordPress plugin by Crocoblock, affecting versions through 3.6.1.

Is CVE-2026-54196 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 16, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? The CVSS vector indicates low privileges are required (PR:L), meaning an attacker needs some existing, low-level account access to the affected site.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions through 3.6.1 are affected. Consult the plugin vendor directly for the current patched release.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-54196, corroborated by Patchstack’s vulnerability database entry. Exploitation status and the September 16, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools