CVE-2026-14864
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.
| Vendor | unknown |
| Product | jetengine |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown jetengine
Be the first to know when new unknown vulnerabilities affecting unknown jetengine are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / JetEngine
0 < 3.8.12
References
Credits
axbqd WPScan