Junglewise Threat Intelligence

CVE-2026-14864: Crocoblock JetEngine stored XSS via unescaped shortcode meta output

CVE-2026-14864 · Severity: medium · CVSS 5.4 · Published 2026-08-02

Technologies: Crocoblock JetEngine. Vendors: Crocoblock.

Executive brief

JetEngine is a WordPress plugin that provides dynamic content display through shortcodes. A vulnerability in the plugin allows contributors to inject malicious scripts that execute in administrators' browsers when they view content, potentially leading to account compromise and privilege escalation.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in JetEngine's shortcode handler. The root cause is the failure to escape post meta values retrieved via get_post_meta() before outputting them through the [jet_engine field="KEY"] shortcode. An attacker with Contributor role can create a pending post with a shortcode placeholder and store malicious HTML in post metadata via XML-RPC, bypassing WordPress KSES filtering. When an administrator previews or views the post, the shortcode executes and renders the unescaped meta content, triggering the injected JavaScript in the admin's session. This can be leveraged to steal nonces and create unauthorized administrator accounts. The vulnerability affects JetEngine before version 3.8.12 and is fixed in 3.8.12.

Affected products

  • Crocoblock JetEngine before 3.8.12

Timeline

  • 2026-07-20: disclosed
  • 2026-08-02: patched: Fixed in version 3.8.12

References

Related threats