CVE-2026-97265: WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS.
This issue affects JetEngine: from n/a through 3.8.15.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetEngine pluginto a version that resolves this vulnerability.Fixed in 3.8.15.4
Event History
Frequently Asked Questions
What level of access and interaction are required to exploit this issue?
The attack vector is network-based and has low attack complexity, but the attacker needs low-level privileges and user interaction. The issue is a stored XSS vulnerability.
Which installations should be considered affected?
JetEngine versions through 3.8.15.3 are identified as affected. The affected version range begins at an unspecified version.
How can I determine whether my site is exposed?
Check whether JetEngine is installed and identify its installed version. Treat installations at version 3.8.15.3 or earlier as affected based on the available information.