CVE-2026-19860 | JetFormBuilder Plugin 3.6.0/3.6.5.2 on WordPress Custom Field-Validation Callback file inclusion

SecurityVulns

A vulnerability was found in JetFormBuilder Plugin 3.6.0/3.6.5.2 on WordPress. It has been declared as critical. The impacted element is an unknown function of the component Custom Field-Validation Callback. Executing a manipulation can lead to file inclusion.

The identification of this vulnerability is CVE-2026-19860. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More