Executive brief
JetEngine is a popular WordPress plugin used for creating dynamic website content and custom data structures. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to visitors. This occurs when a victim, such as a site administrator, interacts with a specially crafted link or page.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the JetEngine plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The vulnerability is exploitable by unauthenticated remote attackers and requires user interaction (typically from a privileged user) to execute. Successful exploitation allows an attacker to inject arbitrary HTML or JavaScript payloads into the context of the victim's browser session. This can lead to session hijacking, unauthorized administrative actions, or site defacement. The issue is resolved in version 3.8.10.
Affected products
- Crocoblock (Jetimpex Inc.) JetEngine <= 3.8.9.1
Timeline
- 2026-05-19: other: Reported by researcher daroo
- 2026-06-08: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: NVD publication date