Executive brief
JetEngine is a popular WordPress plugin used to create dynamic content and custom website structures. A security flaw in versions up to 3.8.10 allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the JetEngine plugin for WordPress (versions <= 3.8.10) due to improper neutralization of input during web page generation (CWE-79). The vulnerability is unauthenticated, meaning an attacker does not need an account on the target site to initiate the attack. However, successful exploitation requires user interaction, such as a victim clicking a malicious link or visiting a crafted page. This can lead to the execution of arbitrary JavaScript in the context of the victim's browser session, potentially allowing for session hijacking or site defacement. The issue is resolved in version 3.8.10.1.
Affected products
- Jetimpex Inc. (Crocoblock) JetEngine <= 3.8.10
Timeline
- 2026-06-08: other: Reported by VanTastic
- 2026-06-16: disclosed: Published by Patchstack
- 2026-06-17: advisory: NVD published date
- 2026-06-17: patched: Patch available in version 3.8.10.1