PT-2026-69360 · WordPress · Jetengine
CVE-2026-17019
·
Published
2026-08-10
·
Updated
2026-08-10
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JetEngine WordPress plugin versions prior to 3.8.13.1
Description
Stored Cross-Site Scripting occurs because the software fails to sanitize uploaded SVG files before storing and serving them. Additionally, the system does not adequately restrict upload permissions, allowing unauthenticated attackers to upload files containing malicious JavaScript. This script executes in the browser of any user who opens the uploaded file.
Recommendations
Update JetEngine WordPress plugin to version 3.8.13.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetengine