CVE-2025-49938: WordPress JetEngine plugin <= 3.7.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49938?
CVE-2025-49938 is classified as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-49938?
To fix CVE-2025-49938, update CrocoBlock JetEngine to version 3.7.4 or later, which addresses the vulnerability.
What versions are affected by CVE-2025-49938?
CVE-2025-49938 affects CrocoBlock JetEngine versions up to and including 3.7.3.
What should I do if I cannot update due to dependency issues with CVE-2025-49938?
If you cannot update, consider implementing web application firewall rules to mitigate risks from CVE-2025-49938.
Can CVE-2025-49938 be exploited remotely?
Yes, CVE-2025-49938 can be exploited remotely by attackers to execute scripts in the context of the user's browser.