Junglewise Threat Intelligence

CVE-2026-81760: Crocoblock JetEngine reflected cross-site scripting (XSS)

CVE-2026-81760 · Severity: high · CVSS 7.1 · Published 2026-08-28

Technologies: Crocoblock JetEngine. Vendors: Crocoblock.

Executive brief

JetEngine is a WordPress plugin used to build dynamic content and manage complex data relationships on websites. A reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that steal visitor data or hijack user accounts when victims click a crafted link or visit a malicious page.

Technical details

This vulnerability is a reflected cross-site scripting (XSS) flaw in JetEngine (versions through 3.8.14.2) caused by improper neutralization of user input during web page generation. The vulnerability is accessible to unauthenticated attackers but requires user interaction—a victim must click a malicious link or visit a crafted page for the attack to succeed. Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the victim's browser, enabling theft of session cookies, account hijacking, or malware distribution. The issue is patched in version 3.8.14.3 and later.

Affected products

  • Crocoblock JetEngine through 3.8.14.2

Timeline

  • 2026-08-27: disclosed: Reported by dutafi
  • 2026-08-28: advisory: Published on NVD
  • 2026: patched: Fixed in version 3.8.14.3 or later

References

Related threats