What is CVE-2026-28140?
CVE-2026-28140 is an unauthenticated broken access control vulnerability in JetFormBuilder plugin. It affects versions up to 3.6.4.1. Immediate update to the latest version is required to prevent exploitation.
Azərbaycanca: CVE-2026-28140 JetFormBuilder plaginində autentifikasiya olunmadan broken access control zəifliyidir. Bu, 3.6.4.1 və daha əvvəlki versiyalara təsir edir. İstismar qarşısını almaq üçün dərhal son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin and which versions are affected by CVE-2026-28140?
CVE-2026-28140 was discovered in the JetFormBuilder plugin and affects versions up to and including 3.6.4.1.
How can I protect against this broken access control vulnerability?
To prevent exploitation, you must immediately update the JetFormBuilder plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.