CVE-2026-66613: WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
Published Aug 19, 2026
·Updated
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Affected Software
1 affected component
WordPress JetEngine Plugin<=3.8.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetEngine Pluginto a version that resolves this vulnerability.Fixed in 3.8.14.1
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated and remotely exploitable, so an attacker does not need a WordPress account or user interaction to attempt exploitation.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in remote code execution with high impact to confidentiality, integrity, and availability.
3
Which deployments are affected?
WordPress sites using the JetEngine plugin version 3.8.14 or earlier are affected according to the available data.