CVE-2024-7291

JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation

The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as super-admins on the sites configured as multi-sites.


We have discovered 2,180 live websites that are affected by CVE-2024-7291.

Run a Free Instant Scan




Affected Software

Product  Jetformbuilder
Category Wordpress Plugins
Vulnerable Domains2,180 live websites (38% of Jetformbuilder install base)
Vulnerable Versions
  • from 0 through 3.3.4.1
Vulnerable Versions Count36 versions ( 59% of all versions)


Common Weakness Enumeration

CWE-269 Improper Privilege Management



Details

  • Published - Aug 3, 2024
  • Updated - Apr 8, 2026

Credits

  • István Márton (finder)

Website Distribution by Country

Number of websites using CVE-2024-7291
United States429 websites



Germany219 websites
Brazil207 websites
Netherlands118 websites
France117 websites
Spain94 websites
GB75 websites
Bulgaria70 websites
Canada56 websites
Belgium51 websites

Website Distribution by TLD

Number of websites using CVE-2024-7291
.com743 websites
.com.br167 websites
.de126 websites
.org102 websites
.nl99 websites
.fr53 websites
.ch42 websites
.it40 websites
.at39 websites
.co.uk36 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7291

Top websites that are affected by CVE-2024-7291. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
**********.com United States**,***
*****.org United States**,***
****.********.edu United States**,***
*******.com Cyprus***,***
*******************.de Germany***,***
**************.org United States***,***
*************.com Canada***,***
***********.eu Portugal***,***
***********************.fr France***,***
See full domain list

FAQ

CVE-2024-7291 is Improper Privilege Management in Jetformbuilder
A total of 2,180 websites have been identified as vulnerable to CVE-2024-7291, based on global website indexing conducted by WebTechSurvey.
The Jetformbuilder is affected by the CVE-2024-7291 vulnerability.
Jetformbuilder versions up to and including 3.3.4.1 are vulnerable to CVE-2024-7291.