CVE-2026-14864: JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
Published Aug 2, 2026
·Updated
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.
Affected Software
1 affected component
Crocoblock JetEngine<3.8.12
Event History
Aug 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14864?
CVE-2026-14864 has a risk score of 45.
2
How do I fix CVE-2026-14864?
To fix CVE-2026-14864, update the JetEngine plugin to version 3.8.12 or later.
3
What type of vulnerability is CVE-2026-14864?
CVE-2026-14864 is categorized as a Stored Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-14864?
CVE-2026-14864 affects users with the Contributor role and above in the JetEngine WordPress plugin.
5
What can attackers do with CVE-2026-14864?
Attackers can exploit CVE-2026-14864 to perform Stored XSS attacks that execute in the context of higher-privileged users.