WordPress · Jetengine · CVE-2026-14864
**Name of the Vulnerable Software and Affected Versions**
JetEngine versions prior to 3.8.12
**Description**
Stored Cross-Site Scripting (XSS) occurs because the plugin fails to escape a post meta value before outputting it through a shortcode. This allows users with the Contributor role or higher to execute malicious scripts in the context of users with higher privileges, such as administrators.
**Recommendations**
Update JetEngine to version 3.8.12 or later.