Impact
An unauthenticated Remote Code Execution vulnerability exists in JetEngine versions up to 3.8.14 that allows an attacker to run arbitrary code on a WordPress site. The weakness is due to improper handling of user input, which is classified as CWE-1336. If exploited, an attacker can achieve total compromise of the target system, including data theft, defacement, or further lateral movement.
Affected Systems
Crocoblock's WordPress JetEngine plugin, including Jetimpex Inc. JetEngine, version 3.8.14 or earlier. Sites that have not upgraded beyond 3.8.14 are affected.
Risk and Exploitability
The CVSS score of 9.8 places this issue in the Critical severity range, indicating that exploitation would have a severe impact. The EPSS score is <1%, indicating a very low probability of exploitation. This vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending specially crafted HTTP requests to plugin endpoints without needing authentication, making the attack vectored as unauthenticated remote. Once the flaw is triggered, arbitrary PHP code can be injected and executed on the host.
OpenCVE Enrichment