Impact
The JetEngine WordPress plugin before version 3.8.13.1 fails to sanitise SVG files uploaded via its form interface. An unauthenticated attacker can upload a malicious SVG containing JavaScript; when any site visitor opens the file, the embedded script executes in the visitor’s browser. This Stored XSS flaw allows an attacker to deface content, steal session cookies, or perform other browser‑based attacks against all users whose browsers display the injected content.
Affected Systems
The vulnerability affects all installations of the JetEngine plugin for WordPress that are running a version earlier than 3.8.13.1. No other vendors or products are listed as affected.
Risk and Exploitability
Because the flaw is unauthenticated and relies on a commonly used file‑upload feature, any visitor who views the injected SVG can be impacted. The EPSS score is reported as <1%, indicating a very low but nonzero probability of exploitation. The EPSS score does not eliminate the risk, especially given the moderate CVSS score of 6.1. The vulnerability is not yet listed in the CISA KEV catalog. Attackers could exploit the flaw by uploading a malicious SVG file and then luring site users to view the file, which triggers script execution in the victim’s browser.
OpenCVE Enrichment