Executive brief
JetEngine is a WordPress plugin used to build dynamic content and manage complex data relationships on websites. A reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that steal visitor data or hijack user accounts when victims click a crafted link or visit a malicious page.
Technical details
This vulnerability is a reflected cross-site scripting (XSS) flaw in JetEngine (versions through 3.8.14.2) caused by improper neutralization of user input during web page generation. The vulnerability is accessible to unauthenticated attackers but requires user interaction—a victim must click a malicious link or visit a crafted page for the attack to succeed. Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the victim's browser, enabling theft of session cookies, account hijacking, or malware distribution. The issue is patched in version 3.8.14.3 and later.
Affected products
- Crocoblock JetEngine through 3.8.14.2
Timeline
- 2026-08-27: disclosed: Reported by dutafi
- 2026-08-28: advisory: Published on NVD
- 2026: patched: Fixed in version 3.8.14.3 or later