Sceawere
Vulnerability Detail
CVE-2026-97237UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in JetEngine
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Crocoblock. Jetimpex Inc.
- Product
- JetEngine
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:35.357Z",
"pubdate": "2026-09-30T13:17:35.357Z",
"executiveSummary": "JetEngine versions 3.8.14.3 and below are susceptible to an Unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw enables remote, unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session. By successfully exploiting this vulnerability, an attacker can bypass standard security controls to manipulate page content, intercept sensitive user data, or perform unauthorized actions on behalf of authenticated administrators. Because the vulnerability does not require authentication, it significantly lowers the barrier for exploitation, exposing affected WordPress installations to cross-site scripting attacks that can lead to session hijacking, defacement, or the distribution of malicious payloads. The risk level is elevated due to the prevalence of JetEngine in dynamic content rendering, meaning successful execution could impact high-privilege users visiting the site.",
"technicalDetails": "The vulnerability resides in the input handling mechanism of JetEngine versions 3.8.14.3 and below, where user-supplied data is processed and reflected in the browser without adequate sanitization or output encoding. The root cause is the failure to neutralize dangerous characters or scripts within specific dynamic query parameters or form fields managed by the plugin's internal components. This lack of robust input validation allows an attacker to inject malicious JavaScript payloads into the DOM (Document Object Model).\nThe attack flow begins when an unauthenticated attacker crafts a URL containing a malicious script payload designed to interact with JetEngine's rendering logic. Upon visiting the crafted link, the victim's browser processes the unsanitized input as part of the page content. Because the execution occurs within the origin of the vulnerable site, the script gains access to the user's document object, including cookies, session tokens, and local storage. If an administrator is targeted, the attacker could theoretically perform administrative actions, such as modifying plugin configurations, creating new users, or injecting backdoors into the theme files.\nExploitation does not require prior knowledge of the target's credentials or a pre-existing authenticated session. The attack is inherently client-side, relying on the victim's browser to interpret the injected tags (e.g., <script>, <img> tags with onerror attributes) as legitimate executable code. The vulnerable component is likely associated with the plugin's dynamic rendering engine, which processes input parameters to dynamically generate site content. As the rendering process lacks strict context-aware output encoding, the script is rendered directly into the HTML structure. Once the payload is triggered, it persists in the rendered page for any user who follows the malicious link, facilitating mass-exploitation scenarios. Post-exploitation, the impact is strictly governed by the victim's privilege level, but in the case of administrative targets, the compromise leads to full system control or significant security degradation."
}