๐Ÿ” CVE Alert

CVE-2026-18202

UNKNOWN 0.0

JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.

Vendor unknown
Product jetengine
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown jetengine

Be the first to know when new unknown vulnerabilities affecting unknown jetengine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / JetEngine
0 < 3.8.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/911d3b5a-0f03-4423-b4b0-84e588c323d8/

Credits

Erwan LR (WPScan) WPScan