Impact
The JetEngine plugin for WordPress contains a contributor‑level Server Side Request Forgery vulnerability in all versions up to 3.8.11. This flaw allows an attacker to supply an arbitrary URL to the plugin and force the server to perform an HTTP request to that target. The attacker can therefore access internal network resources or sensitive external endpoints that would otherwise be inaccessible from the public network.
Affected Systems
WordPress sites that use the JetEngine plugin, provided by Crocoblock and Jetimpex Inc. All releases of JetEngine through version 3.8.11 are vulnerable; the issue is fixed in 3.8.12 and later.
Risk and Exploitability
The vulnerability is rated a moderate CVSS score of 4.9 and has an EPSS score of less than 1 %, indicating a low probability of exploitation. It is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring user interaction to trigger the vulnerable request from the web interface, but no additional access or privileges are needed once the SSRF is activated.
OpenCVE Enrichment