Impact
The JetEngine plugin has a stored cross‑site scripting flaw that improperly neutralizes input when generating web pages. An attacker can inject malicious script into data fields that are later rendered for all site visitors, leading to client‑side code execution, theft of session cookies, or defacement of the site. This weakness is an instance of CWE‑79, which is a classic input validation flaw that allows attacker-supplied code to run in unwary browsers.
Affected Systems
The vulnerability is present in Crocoblock JetEngine (Jetimpex Inc.) plugin versions from the initial release up to and including 3.8.15.3. Any WordPress site that has JetEngine installed at or below this version is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS figure is provided, so the exploitation probability remains unknown, but the flaw is listed as a stored XSS which is generally straightforward to exploit in a website with editable content. The vulnerability is not part of the CISA KEV list, but patching remains advisable to eliminate the risk of unintended script execution by malicious actors.
OpenCVE Enrichment