CVE-2026-66581: WordPress JetEngine plugin <= 3.8.14.1 - Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Affected Software
1 affected component
WordPress JetEngine Plugin<=3.8.14.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/JetEngineto a version that resolves this vulnerability.Fixed in 3.8.14.2
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication is required. The attack vector is network-based, but exploitation requires user interaction.
2
What security impact can successful exploitation have?
The issue is rated high severity with a CVSS score of 7.1. It can affect confidentiality, integrity, and availability at low impact, and its scope is changed.