Impact
Unauthenticated Cross Site Scripting (XSS) has been identified in the WordPress JetEngine plugin versions 3.8.13.1 and earlier. The flaw allows an attacker to insert malicious JavaScript into editable content fields within the plugin. When other visitors load the affected page, the script would execute in their browser context. While the vulnerability does not grant direct code execution on the server, it can potentially be used, inferred, to hijack user sessions, steal cookies, or carry out phishing attacks. The weakness arises from insufficient input validation, corresponding to CWE‑79.
Affected Systems
The defect impacts all installations of the WordPress JetEngine plugin provided by Crocoblock, also known as JetEngine from Jetimpex Inc. The vulnerability applies to any site running JetEngine version 3.8.13.1 or earlier, regardless of customizations. Any WordPress installation using these versions is susceptible.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. No EPSS score is recorded, so the probability of exploitation remains unquantified. The plugin does not appear in the CISA KEV catalog, indicating no confirmed active exploits. Likely attack vectors include the web interface, as authentication is not required; an unauthenticated visitor can craft a malicious request to inject the payload into editable fields, leading to script execution for subsequent users. The lack of a publicly documented exploit does not diminish the risk, as the vulnerability is exploitable by anyone with access to the site’s front‑end.
OpenCVE Enrichment