JetFormBuilder
BitFire's FREE WAF blocks the malicious query-string payloads behind the JetFormBuilder CVE-2026-92212 reflected XSS before WordPress processes the request.
- Affected sites
- 80000
- Attack class
- Reflected Cross-site Scripting
Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.
Showing 7–12 of 44 records · Updated September 29, 2026
BitFire's FREE WAF blocks the malicious query-string payloads behind the JetFormBuilder CVE-2026-92212 reflected XSS before WordPress processes the request.
CVE-2026-89426 lets any Knit Pay 9.6.1.0 user become administrator via Gravity Forms. BitFire FREE Bot Protection and PRO RASP stop the chain.
BitFire FREE Bot Protection and WAF stop the unauthenticated AJAX delivery and script payload behind CVE-2026-84281 before Fancy Product Designer stores it.
BitFire's WAF blocks the script-injection payloads behind CVE-2026-84280, a stored XSS flaw in Fancy Product Designer exploitable by unauthenticated attackers.
BitFire's FREE WAF and Bot Protection stop the unauthenticated Contact Form 7 POST that plants stored XSS in Zero Spam's admin Detection Log.
An unauthenticated checkout field stores JavaScript that executes in admin browsers; BitFire FREE's WAF blocks the malicious POST before WordPress stores it.
Page 2 of 8
BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.