CVE-2025-53194: WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerability
Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Code Injection.This issue affects JetEngine: from n/a through <= 3.7.0.
Other sources
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Crocoblock JetEngine allows Code Injection. This issue affects JetEngine: from n/a through 3.7.0.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53194?
CVE-2025-53194 has a high severity due to its potential for code injection, which can lead to remote code execution.
How do I fix CVE-2025-53194?
To fix CVE-2025-53194, update Crocoblock JetEngine to version 3.7.1 or later.
Which versions of JetEngine are affected by CVE-2025-53194?
CVE-2025-53194 affects JetEngine versions from n/a through 3.7.0.
What type of vulnerability is CVE-2025-53194?
CVE-2025-53194 is categorized as an Improper Neutralization of Special Elements Used in a Template Engine vulnerability.
Where can I find more information about CVE-2025-53194?
Detailed information regarding CVE-2025-53194 can typically be found in security advisories from Crocoblock or trusted cybersecurity resources.