Description
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Published: 2026-08-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Patch
AI Analysis

Impact

Unauthenticated Cross Site Scripting vulnerability is present in all JetEngine plugin versions up to 3.8.14.1. A malicious script can be injected through an input field that is rendered in the front‑end of a WordPress site, allowing an attacker to execute arbitrary JavaScript in the browsers of unsuspecting visitors. The weakness is classified as CWE‑79, meaning improper input validation and output encoding.

Affected Systems

All installations of the JetEngine plugin distributed by Crocoblock and Jetimpex Inc. that are running version 3.8.14.1 or older. Sites that use the plugin and expose its input handling routes to the public are susceptible; there is no restriction to authenticated users.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high impact, and because the attack requires no authentication, any website visitor can trigger the flaw. The EPSS score is not available, so we cannot quantify the current exploit probability, but the lack of a KEV listing shows no known widespread exploitation yet. An attacker would typically target a site that relies on JetEngine for data presentation or form handling, inject malicious payloads via exposed fields, and then harvest user sessions or deface the site.

Generated by OpenCVE AI on August 20, 2026 at 22:27 UTC.

Remediation

Vendor Solution

Update the WordPress JetEngine Plugin to the latest available version (at least 3.8.14.2).


OpenCVE Recommended Actions

  • Upgrade the WordPress JetEngine Plugin to version 3.8.14.2 or newer, which removes the XSS bug.
  • If an upgrade cannot be performed immediately, restrict public access to JetEngine‑driven input endpoints by configuring role‑based permissions or a firewall rule to block unauthenticated requests.
  • Deploy a Web Application Firewall or content‑security‑policy that sanitizes or rejects injected JavaScript payloads targeting JetEngine input fields.

Generated by OpenCVE AI on August 20, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock. Jetimpex Inc.
Crocoblock. Jetimpex Inc. jetengine
Wordpress
Wordpress wordpress
Vendors & Products Crocoblock. Jetimpex Inc.
Crocoblock. Jetimpex Inc. jetengine
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Title WordPress JetEngine plugin <= 3.8.14.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crocoblock. Jetimpex Inc. Jetengine
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T14:31:02.807Z

Reserved: 2026-07-27T13:59:59.781Z

Link: CVE-2026-66581

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:32.420

Modified: 2026-08-20T15:18:15.553

Link: CVE-2026-66581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:15:45Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')