Sceawere

Vulnerability Detail

CVE-2026-97237UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in JetEngine

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Crocoblock. Jetimpex Inc.
Product
JetEngine
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:35.357Z",
  "pubdate": "2026-09-30T13:17:35.357Z",
  "executiveSummary": "JetEngine versions 3.8.14.3 and below are susceptible to an Unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw enables remote, unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session. By successfully exploiting this vulnerability, an attacker can bypass standard security controls to manipulate page content, intercept sensitive user data, or perform unauthorized actions on behalf of authenticated administrators. Because the vulnerability does not require authentication, it significantly lowers the barrier for exploitation, exposing affected WordPress installations to cross-site scripting attacks that can lead to session hijacking, defacement, or the distribution of malicious payloads. The risk level is elevated due to the prevalence of JetEngine in dynamic content rendering, meaning successful execution could impact high-privilege users visiting the site.",
  "technicalDetails": "The vulnerability resides in the input handling mechanism of JetEngine versions 3.8.14.3 and below, where user-supplied data is processed and reflected in the browser without adequate sanitization or output encoding. The root cause is the failure to neutralize dangerous characters or scripts within specific dynamic query parameters or form fields managed by the plugin's internal components. This lack of robust input validation allows an attacker to inject malicious JavaScript payloads into the DOM (Document Object Model).\nThe attack flow begins when an unauthenticated attacker crafts a URL containing a malicious script payload designed to interact with JetEngine's rendering logic. Upon visiting the crafted link, the victim's browser processes the unsanitized input as part of the page content. Because the execution occurs within the origin of the vulnerable site, the script gains access to the user's document object, including cookies, session tokens, and local storage. If an administrator is targeted, the attacker could theoretically perform administrative actions, such as modifying plugin configurations, creating new users, or injecting backdoors into the theme files.\nExploitation does not require prior knowledge of the target's credentials or a pre-existing authenticated session. The attack is inherently client-side, relying on the victim's browser to interpret the injected tags (e.g., <script>, <img> tags with onerror attributes) as legitimate executable code. The vulnerable component is likely associated with the plugin's dynamic rendering engine, which processes input parameters to dynamically generate site content. As the rendering process lacks strict context-aware output encoding, the script is rendered directly into the HTML structure. Once the payload is triggered, it persists in the rendered page for any user who follows the malicious link, facilitating mass-exploitation scenarios. Post-exploitation, the impact is strictly governed by the victim's privilege level, but in the case of administrative targets, the compromise leads to full system control or significant security degradation."
}
CVE-2026-97237: Unauthenticated XSS in JetEngine (HIGH Severity, CVSS: 7.1) | Sceawere