CVE-2022-4997: Unknown Jet-Form-Builder-Stripe-Gateway

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.

Affected products

  • Unknown Jet-Form-Builder-Stripe-Gateway: before 1.1.0 (fixed in 1.1.0)

Published 2026-09-23. Last modified 2026-09-23.