Impact
JetEngine versions prior to 3.8.14 add the SVG MIME type to the list of allowed upload types without sanitising the file contents. This permits users with upload permissions, such as Authors, to upload an SVG file that contains malicious JavaScript. When any user views the file, the script executes in the browser, leading to a Stored Cross‑Site Scripting (XSS) vulnerability. The attack can expose sensitive data, hijack sessions, and allow further malicious activities on the WordPress site.
Affected Systems
The vulnerability exists in the JetEngine WordPress plugin for all installations using a version older than 3.8.14. It affects single‑site and multi‑site WordPress deployments, and on multisite it also unintentionally overrides network‑wide upload‑type restrictions set by the administrator.
Risk and Exploitability
With a CVSS score of 6.8, this flaw is considered moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The flaw is not currently listed in the CISA KEV catalogue. Attackers can exploit the vulnerability by uploading a crafted SVG file while holding a user role with upload capability; the stored payload then runs in any user's browser that opens the file. No remote code execution or privilege escalation beyond the browser context is described in the current data.
OpenCVE Enrichment