ZeroHour

CVE-2026-81760

large

Reflected XSS in Crocoblock JetEngine WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

JetEngine, a Crocoblock plugin for WordPress that generates dynamic content on pages, does not properly neutralize input that is reflected into generated web pages, enabling reflected cross-site scripting (CWE-79). An unauthenticated attacker can craft a malicious URL whose parameters are echoed back into the rendered page without sanitization; if a victim clicks the link, the injected script executes in the victim's browser in the context of the affected site. Successful exploitation could let an attacker hijack the session of a logged-in user (including administrators who click the link), perform actions on their behalf, or redirect visitors. Any WordPress site running JetEngine up to and including version 3.8.14.2 is affected, and exploitation requires user interaction to trigger (consistent with the CVSS score of 7.1). There is currently no public proof-of-concept, no CISA KEV listing, and EPSS is low (0.1%), so no confirmed exploitation activity is known.

What to do: Update JetEngine to a patched release newer than 3.8.14.2 as soon as one is available, and verify the installed version under WordPress Plugins. Until patched, be cautious with unsolicited links pointing to affected sites and consider reviewing access logs for requests with unusual reflected parameters. No known public exploit lowers immediate urgency, but the flaw is unauthenticated and network-exploitable, so patching should remain a priority.

Affected
Crocoblock JetEngine
Estimated exposure
large≈100,000+ WordPress sites (JetEngine's public active-install counts are on the order of 100k) — The estimate is based on JetEngine's WordPress.org active-install statistics, which have been reported at roughly the 100,000-site mark for this widely deployed Crocoblock dynamic-content plugin.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.