plugin

Jet Engine Vulnerabilities

53 known security issues reported for the Jet Engine WordPress plugin. Most recent disclosed Aug 21, 2026.

2 critical 23 high 13 medium

Running Jet Engine on your site? Check whether your installed version is affected.

Scan your site free

JetEngine < 3.8.14 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.8.14. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will exe...

CVSS:
6.4
Affected:
up to 3.8.14
Fixed in:
3.8.14
Disclosed:
Aug 21, 2026

CVE-2026-18202 on NVD →

JetEngine <= 3.8.14 - Unauthenticated Remote Code Execution

critical

The JetEngine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.8.14. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for unauthenticated attackers to execute arbitrary code on the server.

CVSS:
9.8
Affected:
up to 3.8.14
Fixed in:
3.8.14.1
Disclosed:
Aug 19, 2026

CVE-2026-66613 on NVD →

JetEngine <= 3.8.14.1 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.8.14.1. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u...

CVSS:
7.2
Affected:
up to 3.8.14.1
Fixed in:
3.8.14.2
Disclosed:
Aug 19, 2026

CVE-2026-66581 on NVD →

JetEngine <= 3.8.13.0 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
7.2
Affected:
up to 3.8.13.0
Fixed in:
3.8.13.1
Disclosed:
Aug 5, 2026

CVE-2026-17019 on NVD →

JetEngine <= 3.8.13.1 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
7.2
Affected:
up to 3.8.13.1
Fixed in:
3.8.13.2
Disclosed:
Aug 3, 2026

CVE-2026-28082 on NVD →

JetEngine < 3.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whe...

CVSS:
6.4
Affected:
up to 3.8.12
Fixed in:
3.8.12
Disclosed:
Aug 2, 2026

CVE-2026-14864 on NVD →

JetEngine <= 3.8.11 - Authenticated (Contributor+) Sever-Side Request Forgery

medium

The JetEngine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.8.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to...

CVSS:
6.4
Affected:
up to 3.8.11
Fixed in:
3.8.12
Disclosed:
Jul 22, 2026

CVE-2026-65467 on NVD →

JetEngine <= 3.8.10.2 - Unauthenticated SQL Injection

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...

CVSS:
7.5
Affected:
up to 3.8.10.2
Fixed in:
3.8.11
Disclosed:
Jun 25, 2026

CVE-2026-56068 on NVD →

JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint

high

The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values...

CVSS:
7.5
Affected:
up to 3.8.10.1
Fixed in:
3.8.10.2
Disclosed:
Jun 16, 2026

CVE-2026-12360 on NVD →

JetEngine <= 3.8.10 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 3.8.10
Fixed in:
3.8.10.1
Disclosed:
Jun 16, 2026

CVE-2026-54188 on NVD →

JetEngine <= 3.8.10 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 3.8.10
Fixed in:
3.8.10.1
Disclosed:
Jun 16, 2026

CVE-2026-54189 on NVD →

JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...

CVSS:
7.5
Affected:
up to 3.8.10.1
Fixed in:
3.8.10.2
Disclosed:
Jun 15, 2026

CVE-2026-54187 on NVD →

JetEngine <= 3.8.10 - Unauthenticated PHP Object Injection

high

The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8.10 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via a...

CVSS:
8.1
Affected:
up to 3.8.10
Fixed in:
3.8.10.1
Disclosed:
Jun 12, 2026

CVE-2026-52706 on NVD →

JetEngine < 3.8.9.1 - Unauthenticated SQL Injection

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to 3.8.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existin...

CVSS:
7.5
Affected:
up to 3.8.9.1
Fixed in:
3.8.9.1
Disclosed:
Jun 8, 2026

CVE-2026-49084 on NVD →

JetEngine <= 3.8.9.1 - Unauthenticated SQL Injection

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...

CVSS:
7.5
Affected:
up to 3.8.9.1
Fixed in:
3.8.10
Disclosed:
Jun 8, 2026

CVE-2026-49076 on NVD →

JetEngine <= 3.8.9.1 - Authenticated (Contributor+) PHP Object Injection

high

The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8.9.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
7.5
Affected:
up to 3.8.9.1
Fixed in:
3.8.10
Disclosed:
Jun 8, 2026

CVE-2026-49075 on NVD →

JetEngine <= 3.8.9.1 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses a...

CVSS:
7.2
Affected:
up to 3.8.9.1
Fixed in:
3.8.10
Disclosed:
Jun 8, 2026

CVE-2026-49074 on NVD →

JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...

CVSS:
7.5
Affected:
up to 3.8.8.1
Fixed in:
3.8.8.2
Disclosed:
Apr 30, 2026

CVE-2026-42774 on NVD →

JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of `$wpdb...

CVSS:
7.5
Affected:
up to 3.8.6.1
Fixed in:
3.8.6.2
Disclosed:
Apr 13, 2026

CVE-2026-4352 on NVD →

JetEngine - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter vulnerability

critical

Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter vulnerability

CVSS:
9.3
Affected:
up to 3.8.6.1
Fixed in:
3.8.6.2
Disclosed:
Mar 25, 2026

JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter

high

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks) combined...

CVSS:
7.5
Affected:
up to 3.8.6.1
Fixed in:
3.8.6.2
Disclosed:
Mar 23, 2026

CVE-2026-4662 on NVD →

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

high

The JetEngine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVSS:
8.8
Affected:
up to 3.7.2
Fixed in:
3.8.1.2
Disclosed:
Feb 26, 2026

CVE-2026-28134 on NVD →

JetEngine [jet-engine] <= 3.8.0 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

Affected:
up to 3.8.0
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-68495 on NVD →

JetEngine < 3.8.4.1 - Authenticated (Contributor+) PHP Object Injection

high

The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.8.4.1 (exclusive) via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
7.5
Affected:
up to 3.8.4.1
Fixed in:
3.8.4.1
Disclosed:
Feb 14, 2026

CVE-2026-32355 on NVD →

JetEngine <= 3.8.0 - Reflected Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Feb 11, 2026

CVE-2025-68495 on NVD →

JetEngine [jet-engine] <= 3.7.7 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7.

Affected:
up to 3.7.7
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-67923 on NVD →

JetEngine [jet-engine] <= 3.8.1.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.8.1.1.

Affected:
up to 3.8.1.1
Fix:
No patched version reported
Disclosed:
Jan 7, 2026

CVE-2025-69333 on NVD →

JetEngine <= 3.7.7 - Unauthenticated Stored Cross-Site Scripting

high

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 3.7.7
Fixed in:
3.7.8
Disclosed:
Jan 5, 2026

CVE-2025-67923 on NVD →

JetEngine <= 3.8.1.1 - Missing Authorization

medium

The JetEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.8.1.1
Fixed in:
3.8.1.2
Disclosed:
Dec 30, 2025

CVE-2025-69333 on NVD →

JetEngine [jet-engine] <= 3.7.3 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.3.

Affected:
up to 3.7.3
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49938 on NVD →

JetEngine <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 3.7.3
Fixed in:
3.7.4
Disclosed:
Sep 18, 2025

CVE-2025-49938 on NVD →

JetEngine [jet-engine] < 3.7.1.1

unknown

[en] Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Crocoblock JetEngine allows Code Injection. This issue affects JetEngine: from n/a through 3.7.0.

Affected:
up to 3.7.1.1
Fixed in:
3.7.1.1
Disclosed:
Aug 20, 2025

CVE-2025-53194 on NVD →

JetEngine [jet-engine] < 3.7.1.1

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine allows Retrieve Embedded Sensitive Data. This issue affects JetEngine: from n/a through 3.7.0.

Affected:
up to 3.7.1.1
Fixed in:
3.7.1.1
Disclosed:
Aug 20, 2025

CVE-2025-53196 on NVD →

JetEngine [jet-engine] < 3.7.1.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.0.

Affected:
up to 3.7.1.1
Fixed in:
3.7.1.1
Disclosed:
Aug 20, 2025

CVE-2025-53195 on NVD →

JetEngine [jet-engine] < 3.7.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.

Affected:
up to 3.7.2
Fixed in:
3.7.2
Disclosed:
Aug 14, 2025

CVE-2025-54688 on NVD →

JetEngine <= 3.7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 3.7.1.2
Fixed in:
3.7.2
Disclosed:
Jul 30, 2025

CVE-2025-54688 on NVD →

JetEngine <= 3.7.0 - Authenticated (Subscriber+) Information Exposure

medium

The JetEngine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 3.7.0
Fixed in:
3.7.1.1
Disclosed:
Jul 16, 2025

CVE-2025-53196 on NVD →

JetEngine <= 3.7.1 - Authenticated (Contributor+) Server-Side Template Injection to Remote Code Execution

high

The JetEngine plugin for WordPress is vulnerable to Remote Code Execution via SSTI in all versions up to, and including, 3.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVSS:
7.5
Affected:
up to 3.7.1
Fixed in:
3.7.1.1
Disclosed:
Jul 13, 2025

CVE-2025-53194 on NVD →

JetEngine <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 3.7.0
Fixed in:
3.7.1.1
Disclosed:
Jun 27, 2025

CVE-2025-53195 on NVD →

JetEngine [jet-engine] < 3.6.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetEngine allows DOM-Based XSS. This issue affects JetEngine: from n/a through 3.6.4.1.

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Apr 15, 2025

CVE-2025-26870 on NVD →

JetEngine <= 3.6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 3.6.4.1
Fixed in:
3.6.5
Disclosed:
Apr 11, 2025

CVE-2025-26870 on NVD →

Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter

medium

The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbi...

CVSS:
6.4
Affected:
up to 3.6.2
Fixed in:
3.6.3
Disclosed:
Jan 17, 2025

CVE-2025-0369 on NVD →

JetEngine [jet-engine] < 3.2.5

unknown

[en] Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Jan 2, 2025

CVE-2023-48758 on NVD →

JetEngine [jet-engine] < 3.2.5.2

unknown

[en] Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Affected:
up to 3.2.5.2
Fixed in:
3.2.5.2
Disclosed:
Jun 19, 2024

CVE-2023-48761 on NVD →

JetEngine [jet-engine] < 3.2.5

unknown

[en] Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
May 17, 2024

CVE-2023-48757 on NVD →

JetEngine [jet-engine] < 3.2.5.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Affected:
up to 3.2.5.2
Fixed in:
3.2.5.2
Disclosed:
Dec 18, 2023

CVE-2023-48762 on NVD →

JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation

high

The JetEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.2.4. This is due to an unknown issue. This makes it possible for authenticated attackers, with contributor-level access and above, to gain elevated privileges.

CVSS:
8.8
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Nov 28, 2023

CVE-2023-48757 on NVD →

JetEngine <= 3.2.4 - Missing Authorization

high

The JetEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
7.1
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Nov 28, 2023

CVE-2023-48758 on NVD →

Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization

medium

Multiple plugins by Crocoblock for WordPress are vulnerable to unauthorized access due to a missing capability check on an unknown function in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
6.3
Affected:
up to 3.2.5.1
Fixed in:
3.2.5.2
Disclosed:
Nov 28, 2023

CVE-2023-48761 on NVD →

Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery

medium

Multiple plugins by Crocoblock for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into p...

CVSS:
4.3
Affected:
up to 3.2.5.1
Fixed in:
3.2.5.2
Disclosed:
Nov 28, 2023

CVE-2023-48762 on NVD →

JetEngine [jet-engine] < 3.1.3.1

unknown

[en] The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

Affected:
up to 3.1.3.1
Fixed in:
3.1.3.1
Disclosed:
Apr 10, 2023

CVE-2023-1406 on NVD →

Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution

high

The Crocoblock JetEngine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 3.1.3. This makes it possible for authenticated attackers with author-level permissions and above to upload arbitrary files on the affected site's server which may...

CVSS:
8.8
Affected:
up to 3.1.3
Fixed in:
3.1.3.1
Disclosed:
Mar 20, 2023

CVE-2023-1406 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database