JetEngine < 3.8.14 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.8.14. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 6.4
- Affected:
- up to 3.8.14
- Fixed in:
- 3.8.14
- Disclosed:
- Aug 21, 2026
CVE-2026-18202 on NVD →
JetEngine <= 3.8.14 - Unauthenticated Remote Code Execution
critical
The JetEngine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.8.14. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for unauthenticated attackers to execute arbitrary code on the server.
- CVSS:
- 9.8
- Affected:
- up to 3.8.14
- Fixed in:
- 3.8.14.1
- Disclosed:
- Aug 19, 2026
CVE-2026-66613 on NVD →
JetEngine <= 3.8.14.1 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.8.14.1. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u...
- CVSS:
- 7.2
- Affected:
- up to 3.8.14.1
- Fixed in:
- 3.8.14.2
- Disclosed:
- Aug 19, 2026
CVE-2026-66581 on NVD →
JetEngine <= 3.8.13.0 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 7.2
- Affected:
- up to 3.8.13.0
- Fixed in:
- 3.8.13.1
- Disclosed:
- Aug 5, 2026
CVE-2026-17019 on NVD →
JetEngine <= 3.8.13.1 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 7.2
- Affected:
- up to 3.8.13.1
- Fixed in:
- 3.8.13.2
- Disclosed:
- Aug 3, 2026
CVE-2026-28082 on NVD →
JetEngine < 3.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 6.4
- Affected:
- up to 3.8.12
- Fixed in:
- 3.8.12
- Disclosed:
- Aug 2, 2026
CVE-2026-14864 on NVD →
JetEngine <= 3.8.11 - Authenticated (Contributor+) Sever-Side Request Forgery
medium
The JetEngine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.8.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to...
- CVSS:
- 6.4
- Affected:
- up to 3.8.11
- Fixed in:
- 3.8.12
- Disclosed:
- Jul 22, 2026
CVE-2026-65467 on NVD →
JetEngine <= 3.8.10.2 - Unauthenticated SQL Injection
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...
- CVSS:
- 7.5
- Affected:
- up to 3.8.10.2
- Fixed in:
- 3.8.11
- Disclosed:
- Jun 25, 2026
CVE-2026-56068 on NVD →
JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint
high
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values...
- CVSS:
- 7.5
- Affected:
- up to 3.8.10.1
- Fixed in:
- 3.8.10.2
- Disclosed:
- Jun 16, 2026
CVE-2026-12360 on NVD →
JetEngine <= 3.8.10 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 3.8.10
- Fixed in:
- 3.8.10.1
- Disclosed:
- Jun 16, 2026
CVE-2026-54188 on NVD →
JetEngine <= 3.8.10 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 3.8.10
- Fixed in:
- 3.8.10.1
- Disclosed:
- Jun 16, 2026
CVE-2026-54189 on NVD →
JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...
- CVSS:
- 7.5
- Affected:
- up to 3.8.10.1
- Fixed in:
- 3.8.10.2
- Disclosed:
- Jun 15, 2026
CVE-2026-54187 on NVD →
JetEngine <= 3.8.10 - Unauthenticated PHP Object Injection
high
The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8.10 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via a...
- CVSS:
- 8.1
- Affected:
- up to 3.8.10
- Fixed in:
- 3.8.10.1
- Disclosed:
- Jun 12, 2026
CVE-2026-52706 on NVD →
JetEngine < 3.8.9.1 - Unauthenticated SQL Injection
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to 3.8.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existin...
- CVSS:
- 7.5
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.9.1
- Disclosed:
- Jun 8, 2026
CVE-2026-49084 on NVD →
JetEngine <= 3.8.9.1 - Unauthenticated SQL Injection
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...
- CVSS:
- 7.5
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.10
- Disclosed:
- Jun 8, 2026
CVE-2026-49076 on NVD →
JetEngine <= 3.8.9.1 - Authenticated (Contributor+) PHP Object Injection
high
The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8.9.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 7.5
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.10
- Disclosed:
- Jun 8, 2026
CVE-2026-49075 on NVD →
JetEngine <= 3.8.9.1 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses a...
- CVSS:
- 7.2
- Affected:
- up to 3.8.9.1
- Fixed in:
- 3.8.10
- Disclosed:
- Jun 8, 2026
CVE-2026-49074 on NVD →
JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...
- CVSS:
- 7.5
- Affected:
- up to 3.8.8.1
- Fixed in:
- 3.8.8.2
- Disclosed:
- Apr 30, 2026
CVE-2026-42774 on NVD →
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of `$wpdb...
- CVSS:
- 7.5
- Affected:
- up to 3.8.6.1
- Fixed in:
- 3.8.6.2
- Disclosed:
- Apr 13, 2026
CVE-2026-4352 on NVD →
JetEngine - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter vulnerability
critical
Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter vulnerability
- CVSS:
- 9.3
- Affected:
- up to 3.8.6.1
- Fixed in:
- 3.8.6.2
- Disclosed:
- Mar 25, 2026
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter
high
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks) combined...
- CVSS:
- 7.5
- Affected:
- up to 3.8.6.1
- Fixed in:
- 3.8.6.2
- Disclosed:
- Mar 23, 2026
CVE-2026-4662 on NVD →
JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution
high
The JetEngine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 3.7.2
- Fixed in:
- 3.8.1.2
- Disclosed:
- Feb 26, 2026
CVE-2026-28134 on NVD →
JetEngine [jet-engine] <= 3.8.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.
- Affected:
- up to 3.8.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-68495 on NVD →
JetEngine < 3.8.4.1 - Authenticated (Contributor+) PHP Object Injection
high
The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.8.4.1 (exclusive) via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 7.5
- Affected:
- up to 3.8.4.1
- Fixed in:
- 3.8.4.1
- Disclosed:
- Feb 14, 2026
CVE-2026-32355 on NVD →
JetEngine <= 3.8.0 - Reflected Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Feb 11, 2026
CVE-2025-68495 on NVD →
JetEngine [jet-engine] <= 3.7.7 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7.
- Affected:
- up to 3.7.7
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-67923 on NVD →
JetEngine [jet-engine] <= 3.8.1.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.8.1.1.
- Affected:
- up to 3.8.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 7, 2026
CVE-2025-69333 on NVD →
JetEngine <= 3.7.7 - Unauthenticated Stored Cross-Site Scripting
high
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Jan 5, 2026
CVE-2025-67923 on NVD →
JetEngine <= 3.8.1.1 - Missing Authorization
medium
The JetEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.8.1.1
- Fixed in:
- 3.8.1.2
- Disclosed:
- Dec 30, 2025
CVE-2025-69333 on NVD →
JetEngine [jet-engine] <= 3.7.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.3.
- Affected:
- up to 3.7.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-49938 on NVD →
JetEngine <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Sep 18, 2025
CVE-2025-49938 on NVD →
JetEngine [jet-engine] < 3.7.1.1
unknown
[en] Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Crocoblock JetEngine allows Code Injection. This issue affects JetEngine: from n/a through 3.7.0.
- Affected:
- up to 3.7.1.1
- Fixed in:
- 3.7.1.1
- Disclosed:
- Aug 20, 2025
CVE-2025-53194 on NVD →
JetEngine [jet-engine] < 3.7.1.1
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine allows Retrieve Embedded Sensitive Data. This issue affects JetEngine: from n/a through 3.7.0.
- Affected:
- up to 3.7.1.1
- Fixed in:
- 3.7.1.1
- Disclosed:
- Aug 20, 2025
CVE-2025-53196 on NVD →
JetEngine [jet-engine] < 3.7.1.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.0.
- Affected:
- up to 3.7.1.1
- Fixed in:
- 3.7.1.1
- Disclosed:
- Aug 20, 2025
CVE-2025-53195 on NVD →
JetEngine [jet-engine] < 3.7.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.2
- Disclosed:
- Aug 14, 2025
CVE-2025-54688 on NVD →
JetEngine <= 3.7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 3.7.1.2
- Fixed in:
- 3.7.2
- Disclosed:
- Jul 30, 2025
CVE-2025-54688 on NVD →
JetEngine <= 3.7.0 - Authenticated (Subscriber+) Information Exposure
medium
The JetEngine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1.1
- Disclosed:
- Jul 16, 2025
CVE-2025-53196 on NVD →
JetEngine <= 3.7.1 - Authenticated (Contributor+) Server-Side Template Injection to Remote Code Execution
high
The JetEngine plugin for WordPress is vulnerable to Remote Code Execution via SSTI in all versions up to, and including, 3.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
- CVSS:
- 7.5
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1.1
- Disclosed:
- Jul 13, 2025
CVE-2025-53194 on NVD →
JetEngine <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1.1
- Disclosed:
- Jun 27, 2025
CVE-2025-53195 on NVD →
JetEngine [jet-engine] < 3.6.5
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetEngine allows DOM-Based XSS. This issue affects JetEngine: from n/a through 3.6.4.1.
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.5
- Disclosed:
- Apr 15, 2025
CVE-2025-26870 on NVD →
JetEngine <= 3.6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 3.6.4.1
- Fixed in:
- 3.6.5
- Disclosed:
- Apr 11, 2025
CVE-2025-26870 on NVD →
Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter
medium
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbi...
- CVSS:
- 6.4
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.3
- Disclosed:
- Jan 17, 2025
CVE-2025-0369 on NVD →
JetEngine [jet-engine] < 3.2.5
unknown
[en] Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- Jan 2, 2025
CVE-2023-48758 on NVD →
JetEngine [jet-engine] < 3.2.5.2
unknown
[en] Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
- Affected:
- up to 3.2.5.2
- Fixed in:
- 3.2.5.2
- Disclosed:
- Jun 19, 2024
CVE-2023-48761 on NVD →
JetEngine [jet-engine] < 3.2.5
unknown
[en] Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.5
- Disclosed:
- May 17, 2024
CVE-2023-48757 on NVD →
JetEngine [jet-engine] < 3.2.5.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
- Affected:
- up to 3.2.5.2
- Fixed in:
- 3.2.5.2
- Disclosed:
- Dec 18, 2023
CVE-2023-48762 on NVD →
JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation
high
The JetEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.2.4. This is due to an unknown issue. This makes it possible for authenticated attackers, with contributor-level access and above, to gain elevated privileges.
- CVSS:
- 8.8
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- Nov 28, 2023
CVE-2023-48757 on NVD →
JetEngine <= 3.2.4 - Missing Authorization
high
The JetEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 7.1
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- Nov 28, 2023
CVE-2023-48758 on NVD →
Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization
medium
Multiple plugins by Crocoblock for WordPress are vulnerable to unauthorized access due to a missing capability check on an unknown function in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 6.3
- Affected:
- up to 3.2.5.1
- Fixed in:
- 3.2.5.2
- Disclosed:
- Nov 28, 2023
CVE-2023-48761 on NVD →
Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery
medium
Multiple plugins by Crocoblock for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into p...
- CVSS:
- 4.3
- Affected:
- up to 3.2.5.1
- Fixed in:
- 3.2.5.2
- Disclosed:
- Nov 28, 2023
CVE-2023-48762 on NVD →
JetEngine [jet-engine] < 3.1.3.1
unknown
[en] The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
- Affected:
- up to 3.1.3.1
- Fixed in:
- 3.1.3.1
- Disclosed:
- Apr 10, 2023
CVE-2023-1406 on NVD →
Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution
high
The Crocoblock JetEngine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 3.1.3. This makes it possible for authenticated attackers with author-level permissions and above to upload arbitrary files on the affected site's server which may...
- CVSS:
- 8.8
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3.1
- Disclosed:
- Mar 20, 2023
CVE-2023-1406 on NVD →
JetEngine [jet-engine] < 3.6.3
unknown
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.3
CVE-2025-0369 on NVD →