Sceawere
Vulnerability Detail
CVE-2026-97238UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JetEngine Subscriber Cross-Site Scripting
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- Crocoblock. Jetimpex Inc.
- Product
- JetEngine
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-30T13:17:35.483Z",
"pubdate": "2026-09-30T13:17:35.483Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the JetEngine plugin for WordPress in versions 3.8.14.3 and below. This security flaw allows authenticated users with subscriber-level privileges to inject malicious client-side scripts into web pages rendered by the application.\nThe vulnerability occurs due to improper neutralization of input during data processing, which permits the execution of arbitrary JavaScript in the context of an administrator or other users viewing the affected content. Successful exploitation can lead to unauthorized actions, session hijacking, or the defacement of site content.\nGiven that this vulnerability requires at least subscriber-level access, the threat landscape is primarily limited to authenticated users; however, in environments where subscriber registration is open, the attack surface is significantly increased. Mitigation requires updating the JetEngine plugin to the latest patched version to ensure proper input sanitization and output encoding are implemented.",
"technicalDetails": "The vulnerability is a Stored Cross-Site Scripting (XSS) flaw localized within the JetEngine plugin's data handling mechanisms. The root cause lies in the insufficient sanitization of user-supplied data before it is stored in the database and subsequently rendered in the WordPress administrative interface or front-end components.\nIn the affected versions (<= 3.8.14.3), the plugin fails to perform adequate context-aware output encoding or strict input validation on parameters processed by JetEngine's dynamic widgets or dynamic field components. When an attacker with subscriber privileges submits malicious input—specifically crafted JavaScript payloads—the system stores this input directly in the database. When a privileged user, such as an administrator, views the page where this content is rendered, the browser interprets the stored payload as executable script rather than plain text.\nThe attack flow proceeds as follows: First, the attacker identifies a component within JetEngine that accepts user-supplied input or allows the manipulation of dynamic fields. Second, the attacker submits a malicious script payload (e.g., <script>alert('XSS')</script> or more sophisticated document.cookie theft scripts) via the exposed endpoint. Third, the plugin saves this data without stripping or escaping sensitive characters like <, >, or quotes. Finally, when an administrator navigates to the backend interface—such as the JetEngine settings panel, dynamic content dashboard, or a page utilizing the malicious dynamic field—the stored JavaScript executes within the victim's session.\nThis vulnerability is particularly dangerous because it facilitates the execution of code within the administrative context. An attacker can leverage this access to perform actions on behalf of the administrator, such as creating new rogue accounts, modifying plugin configurations, or injecting additional malicious code into site themes or templates. The vulnerability is persistent, meaning the payload triggers every time the affected administrative interface is loaded, effectively maintaining a foothold until the malicious entry is identified and removed from the database.\nThe lack of privilege-based input restriction allows low-privileged users to influence the data integrity of the administrative experience. Because this happens within the WordPress dashboard, it bypasses many perimeter-based security measures, relying entirely on the internal sanitization logic of the JetEngine plugin, which has been proven inadequate in the vulnerable versions."
}