CVE-2025-53990

WordPress JetFormBuilder plugin <= 3.5.1.2 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder allows Object Injection. This issue affects JetFormBuilder: from n/a through 3.5.1.2.


We have discovered 1,908 live websites that are affected by CVE-2025-53990.

Run a Free Instant Scan




Affected Software

Product  Jetformbuilder
Category Wordpress Plugins
Vulnerable Domains1,908 live websites (42% of Jetformbuilder install base)
Vulnerable Versions
  • from 0 through 3.5.1.2
Vulnerable Versions Count50 versions ( 88% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Jul 16, 2025
  • Updated - Jul 18, 2025

Credits

  • Que Thanh Tuan - Blue Rock (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-53990
United States343 websites



Brazil150 websites
Germany146 websites
Bulgaria98 websites
Netherlands86 websites
France84 websites
Spain82 websites
GB63 websites
Italy54 websites
Russia54 websites

Website Distribution by TLD

Number of websites using CVE-2025-53990
.com687 websites
.com.br124 websites
.nl75 websites
.org62 websites
.de62 websites
.it48 websites
.es46 websites
.ru45 websites
.co.uk32 websites
.fr32 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-53990

Top websites that are affected by CVE-2025-53990. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
***********.eu Portugal***,***
********.org United States***,***
************.com United States***,***
*****.pl Poland***,***
*****.edu United States***,***
*****************.nl Netherlands***,***
*****.com Thailand***,***
******.bg Bulgaria***,***
**.***.edu United States***,***
See full domain list

FAQ

CVE-2025-53990 is Deserialization of Untrusted Data in Jetformbuilder
A total of 1,908 websites have been identified as vulnerable to CVE-2025-53990, based on global website indexing conducted by WebTechSurvey.
The Jetformbuilder is affected by the CVE-2025-53990 vulnerability.
Jetformbuilder versions up to and including 3.5.1.2 are vulnerable to CVE-2025-53990.