Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS.

This issue affects JetEngine: from n/a through 3.8.15.3.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The JetEngine plugin has a stored cross‑site scripting flaw that improperly neutralizes input when generating web pages. An attacker can inject malicious script into data fields that are later rendered for all site visitors, leading to client‑side code execution, theft of session cookies, or defacement of the site. This weakness is an instance of CWE‑79, which is a classic input validation flaw that allows attacker-supplied code to run in unwary browsers.

Affected Systems

The vulnerability is present in Crocoblock JetEngine (Jetimpex Inc.) plugin versions from the initial release up to and including 3.8.15.3. Any WordPress site that has JetEngine installed at or below this version is impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. No EPSS figure is provided, so the exploitation probability remains unknown, but the flaw is listed as a stored XSS which is generally straightforward to exploit in a website with editable content. The vulnerability is not part of the CISA KEV list, but patching remains advisable to eliminate the risk of unintended script execution by malicious actors.

Generated by OpenCVE AI on September 30, 2026 at 19:52 UTC.

Remediation

Vendor Solution

Update the WordPress JetEngine plugin to the latest available version (at least 3.8.15.4).


OpenCVE Recommended Actions

  • Update JetEngine to version 3.8.15.4 or newer.
  • Enable or enforce strict content filtering in the plugin settings to strip disallowed HTML from user input.
  • Audit stored content that may contain injected scripts and remove or sanitize suspicious entries.

Generated by OpenCVE AI on September 30, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock. Jetimpex Inc.
Crocoblock. Jetimpex Inc. jetengine
Wordpress-extensions
Wordpress-extensions jetengine
Vendors & Products Crocoblock. Jetimpex Inc.
Crocoblock. Jetimpex Inc. jetengine
Wordpress-extensions
Wordpress-extensions jetengine

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
Title WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crocoblock. Jetimpex Inc. Jetengine
Wordpress-extensions Jetengine
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:55.899Z

Reserved: 2026-09-24T10:23:19.164Z

Link: CVE-2026-97265

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:26.727Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:44.420

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-97265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:35:54Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')