CVE-2026-97237: WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetEngine pluginto a version that resolves this vulnerability.Fixed in 3.8.15
Event History
Frequently Asked Questions
Which JetEngine installations are affected?
JetEngine versions 3.8.14.3 and earlier are affected. The provided information does not identify a fixed version.
Does exploiting this issue require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges.
What access does an attacker need to exploit it?
The CVSS vector indicates network-based exploitation with low attack complexity. It also indicates user interaction is required, meaning a victim must interact with attacker-controlled content or a crafted request.
What is the potential impact if exploitation succeeds?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. This is consistent with XSS potentially affecting users in a different security context.