Horizon Alert
Summary of the vulnerability and why it matters
A critical security vulnerability has been identified in a WordPress plugin used for building forms. This issue could allow unauthorized individuals to create new administrator accounts on affected websites without needing any credentials.
- Forms plugin allows unauthorized admin creation.
- Critical vulnerability exposes WordPress sites.
- Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by submitting a specially crafted form that manipulates the plugin's processing of form IDs. This allows them to bypass normal security checks and directly parse a post's content as a form schema. By exploiting the plugin's failure to validate the form ID, an attacker can trigger server-side validation callbacks, ultimately leading to the creation of a new administrator-level user account on the affected WordPress site.
- No authentication needed.
- Triggers on form submission.
- Allows administrator account creation.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could create new administrator accounts on a WordPress site when the JetFormBuilder plugin is installed. This is possible because the plugin does not properly validate form IDs before processing form data, allowing for the manipulation of form schemas and the execution of server-side validation callbacks.
- Administrator account creation.
- Unauthenticated form submission.
- Unauthorized site control.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WordPress plugin for JetFormBuilder, particularly its dynamic blocks feature, presents a critical privilege escalation vulnerability. This means that teams responsible for WordPress instances, including application owners and platform administrators, must act swiftly. The initial focus should be on identifying all deployments of this plugin, assessing their exposure to unauthenticated access, and then determining the most accountable team for remediation.
- WordPress application and platform owners.
- Verify all plugin installations and exposure.
- Plan coordinated remediation or mitigation.