The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to generate forms using AI, consuming site's AI usage limits.
We have discovered 3,086 live websites that are affected by CVE-2025-11991.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,086 live websites (54% of Jetformbuilder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 55 versions ( 90% of all versions) |
| 593 websites | |
| 309 websites | |
| 248 websites | |
| 165 websites | |
| 162 websites | |
| 141 websites | |
| 113 websites | |
| 105 websites | |
| 85 websites | |
| 84 websites |
| .com | 1,088 websites |
| .com.br | 203 websites |
| .de | 170 websites |
| .nl | 134 websites |
| .org | 127 websites |
| .fr | 72 websites |
| .it | 67 websites |
| .es | 56 websites |
| .ca | 52 websites |
| .ch | 51 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | **,*** | ||
| **********.com | **,*** | ||
| *****.org | **,*** | ||
| ****.********.edu | **,*** | ||
| ****.com | ***,*** | ||
| *******.com | ***,*** | ||
| ***************.com | ***,*** | ||
| *******************.de | ***,*** | ||
| **************.org | ***,*** | ||
| *************.com | ***,*** |
FAQ