Junglewise Threat Intelligence

CVE-2026-17019: JetEngine stored cross-site scripting via SVG file upload

CVE-2026-17019 · Severity: medium · CVSS 6.1 · Published 2026-08-10

Technologies: Crocoblock JetEngine. Vendors: Crocoblock.

Executive brief

JetEngine is a WordPress plugin that enables forms and content creation. The plugin fails to properly validate SVG file uploads, allowing unauthenticated attackers to upload malicious files containing JavaScript code. When site administrators or other users view these files, the embedded malicious code executes in their browser with their privileges, potentially leading to account takeover or unauthorized site modifications.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the JetEngine WordPress plugin versions before 3.8.13.1. The plugin fails to sanitize SVG files before storing them and does not adequately restrict upload permissions, allowing unauthenticated attackers to upload SVG files containing embedded JavaScript. The vulnerable endpoint (jet-engine-forms-upload-file AJAX action) accepts file uploads when a form is configured with file-upload fields set to "Any user" capability. Attackers can extract the upload nonce from public page source, craft a malicious SVG containing JavaScript, and upload it without authentication. The uploaded files are served with image/svg+xml content-type, causing the JavaScript to execute in the context of the site's origin when accessed by any user, particularly administrators. The vulnerability was fixed in version 3.8.13.1.

Affected products

  • Crocoblock JetEngine before 3.8.13.1

Timeline

  • 2026-08-05: disclosed: Publicly disclosed via WPScan
  • 2026-08-10: patched: Fixed in version 3.8.13.1
  • 2026-08-10: advisory: NVD advisory published

References

Related threats