CVE-2023-37866

WordPress JetFormBuilder plugin <= 3.0.8 - Authenticated Privilege Escalation vulnerability

Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.


We have discovered 1,756 live websites that are affected by CVE-2023-37866.

Run a Free Instant Scan




Affected Software

Product  Jetformbuilder
Category Wordpress Plugins
Vulnerable Domains1,756 live websites (31% of Jetformbuilder install base)
Vulnerable Versions
  • from 0 through 3.0.8
Vulnerable Versions Count15 versions ( 25% of all versions)


Common Weakness Enumeration

CWE-269 Improper Privilege Management



Details

  • Published - May 17, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2023-37866
United States351 websites



Germany188 websites
Brazil166 websites
Netherlands105 websites
France98 websites
Spain73 websites
GB67 websites
Belgium50 websites
Canada48 websites
Bulgaria41 websites

Website Distribution by TLD

Number of websites using CVE-2023-37866
.com583 websites
.com.br134 websites
.de116 websites
.org96 websites
.nl86 websites
.fr42 websites
.ch37 websites
.at36 websites
.co.uk34 websites
.be29 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-37866

Top websites that are affected by CVE-2023-37866. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
*****.org United States**,***
****.********.edu United States**,***
*******.com Cyprus***,***
*******************.de Germany***,***
**************.org United States***,***
*************.com Canada***,***
***********************.fr France***,***
***.ca United States***,***
*******.eu France***,***
See full domain list

FAQ

CVE-2023-37866 is Improper Privilege Management in Jetformbuilder
A total of 1,756 websites have been identified as vulnerable to CVE-2023-37866, based on global website indexing conducted by WebTechSurvey.
The Jetformbuilder is affected by the CVE-2023-37866 vulnerability.
Jetformbuilder versions up to and including 3.0.8 are vulnerable to CVE-2023-37866.