CVE-2026-97238: WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
Affected Software
1 affected component
Crocoblock JetEngine<=3.8.14.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetEngine pluginto a version that resolves this vulnerability.Fixed in 3.8.15
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access would an attacker need?
The vulnerability is associated with Subscriber-level access, indicating that a low-privileged authenticated WordPress account is required.
2
Can it be exploited without anyone interacting with attacker-controlled content?
No. The CVSS vector indicates user interaction is required, and exploitation has high attack complexity.
3
What security impact is indicated if exploitation succeeds?
The CVSS vector indicates low impact to confidentiality, integrity, and availability, with scope changed.