Impact
Unauthenticated Cross Site Scripting vulnerability is present in all JetEngine plugin versions up to 3.8.14.1. A malicious script can be injected through an input field that is rendered in the front‑end of a WordPress site, allowing an attacker to execute arbitrary JavaScript in the browsers of unsuspecting visitors. The weakness is classified as CWE‑79, meaning improper input validation and output encoding.
Affected Systems
All installations of the JetEngine plugin distributed by Crocoblock and Jetimpex Inc. that are running version 3.8.14.1 or older. Sites that use the plugin and expose its input handling routes to the public are susceptible; there is no restriction to authenticated users.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high impact, and because the attack requires no authentication, any website visitor can trigger the flaw. The EPSS score is not available, so we cannot quantify the current exploit probability, but the lack of a KEV listing shows no known widespread exploitation yet. An attacker would typically target a site that relies on JetEngine for data presentation or form handling, inject malicious payloads via exposed fields, and then harvest user sessions or deface the site.
OpenCVE Enrichment