JetFormBuilder
cpe:2.3:a:crocoblock:jetformbuilder:*:*:*:*:wordpress:*:*
- <= 3.5.3
A vulnerability exists in the JetFormBuilder WordPress plugin, specifically in versions up to and including 3.5.3. The issue arises from a lack of proper capability checks in the 'run_callback' function, allowing unauthenticated users to generate forms using AI. This exploitation consumes the site's AI usage limits.
Exploitation of this vulnerability allows for unauthorized form generation using AI, which can deplete the site's allocated AI usage resources.
Users are advised to update the JetFormBuilder plugin to version 3.5.4 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.