CVE-2025-54688: WordPress JetEngine Plugin plugin <= 3.7.1.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.1.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54688?
CVE-2025-54688 has a high severity due to its potential for Stored XSS attacks.
How do I fix CVE-2025-54688?
To fix CVE-2025-54688, update Crocoblock JetEngine to the latest version beyond 3.7.1.2.
Who is affected by CVE-2025-54688?
CVE-2025-54688 affects users of Crocoblock JetEngine and WordPress JetEngine Plugin versions up to 3.7.1.2.
What types of attacks can occur due to CVE-2025-54688?
CVE-2025-54688 enables attackers to execute Stored XSS attacks, which can lead to session hijacking and data theft.
Is CVE-2025-54688 easy to exploit?
CVE-2025-54688 is relatively easy to exploit for someone with access to inject malicious scripts into the affected plugin.