---
id: CVE-2026-19862
title: >-
  The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip
  line breaks from address values it sources from submitted form fields before
  adding them to the headers of the e-mails it sends, allowing unauthenticated
  users…
summary: >-
  The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip
  line breaks from address values it sources from submitted form fields before
  adding them to the headers of the e-mails it sends, allowing unauthenticated
  users…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-93
published: '2026-09-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:09:21.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19862'
references:
  - url: 'https://wpscan.com/vulnerability/b3fe5552-6736-4479-9c61-c05bc3328b8e/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00154
epssPercentile: 0.04952
ingestedAt: '2026-09-06T19:59:42.009Z'
---

## Overview

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
