CVE-2026-81760
largeReflected XSS in Crocoblock JetEngine WordPress Plugin
JetEngine, a Crocoblock plugin for WordPress that generates dynamic content on pages, does not properly neutralize input that is reflected into generated web pages, enabling reflected cross-site scripting (CWE-79). An unauthenticated attacker can craft a malicious URL whose parameters are echoed back into the rendered page without sanitization; if a victim clicks the link, the injected script executes in the victim's browser in the context of the affected site. Successful exploitation could let an attacker hijack the session of a logged-in user (including administrators who click the link), perform actions on their behalf, or redirect visitors. Any WordPress site running JetEngine up to and including version 3.8.14.2 is affected, and exploitation requires user interaction to trigger (consistent with the CVSS score of 7.1). There is currently no public proof-of-concept, no CISA KEV listing, and EPSS is low (0.1%), so no confirmed exploitation activity is known.
What to do: Update JetEngine to a patched release newer than 3.8.14.2 as soon as one is available, and verify the installed version under WordPress Plugins. Until patched, be cautious with unsolicited links pointing to affected sites and consider reviewing access logs for requests with unusual reflected parameters. No known public exploit lowers immediate urgency, but the flaw is unauthenticated and network-exploitable, so patching should remain a priority.
| Crocoblock JetEngine | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.