CVE-2026-18202: CWE-79 Cross-Site Scripting (XSS) in JetEngine
CVE-2026-18202 is a stored cross-site scripting (XSS) vulnerability in the JetEngine WordPress plugin versions before 3.8.14. The plugin adds SVG files to the allowed upload types without sanitizing their contents, enabling users with upload permissions to upload malicious SVG files containing JavaScript. This malicious code executes in the browsers of users who open the SVG file. On multisite WordPress installations, this vulnerability also bypasses upload restrictions set by network administrators.
AI Analysis
Technical Summary
The JetEngine WordPress plugin prior to version 3.8.14 improperly allows SVG file uploads without sanitizing the file content. This permits users with upload files capability, such as Authors, to upload SVG files containing malicious JavaScript. When these files are viewed, the embedded script executes in the context of the victim's browser, constituting a stored cross-site scripting (CWE-79) vulnerability. Additionally, in multisite environments, this behavior overrides network administrator upload-type restrictions.
Potential Impact
An attacker with upload permissions can upload malicious SVG files that execute arbitrary JavaScript in the browsers of users who view them. This can lead to theft of sensitive information, session hijacking, or other client-side attacks. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:H/I:H/A:H). On multisite setups, it also circumvents network-level upload restrictions, increasing the attack surface.
Mitigation Recommendations
Upgrade the JetEngine plugin to version 3.8.14 or later where this vulnerability is fixed. Since a patch is available in version 3.8.14, applying this official fix is the recommended remediation. Until upgraded, restrict upload permissions to trusted users only and consider disabling SVG uploads if possible.
CVE-2026-18202: CWE-79 Cross-Site Scripting (XSS) in JetEngine
Description
CVE-2026-18202 is a stored cross-site scripting (XSS) vulnerability in the JetEngine WordPress plugin versions before 3.8.14. The plugin adds SVG files to the allowed upload types without sanitizing their contents, enabling users with upload permissions to upload malicious SVG files containing JavaScript. This malicious code executes in the browsers of users who open the SVG file. On multisite WordPress installations, this vulnerability also bypasses upload restrictions set by network administrators.
CVSS v3.1
Score 6.8medium
Affected software
JetEngine
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The JetEngine WordPress plugin prior to version 3.8.14 improperly allows SVG file uploads without sanitizing the file content. This permits users with upload files capability, such as Authors, to upload SVG files containing malicious JavaScript. When these files are viewed, the embedded script executes in the context of the victim's browser, constituting a stored cross-site scripting (CWE-79) vulnerability. Additionally, in multisite environments, this behavior overrides network administrator upload-type restrictions.
Potential Impact
An attacker with upload permissions can upload malicious SVG files that execute arbitrary JavaScript in the browsers of users who view them. This can lead to theft of sensitive information, session hijacking, or other client-side attacks. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:H/I:H/A:H). On multisite setups, it also circumvents network-level upload restrictions, increasing the attack surface.
Mitigation Recommendations
Upgrade the JetEngine plugin to version 3.8.14 or later where this vulnerability is fixed. Since a patch is available in version 3.8.14, applying this official fix is the recommended remediation. Until upgraded, restrict upload permissions to trusted users only and consider disabling SVG uploads if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-29T07:47:33.859Z
- State
- PUBLISHED
Threat ID: 6a854e93c6e8be033248b28d
Added to database: 08/19/2026, 06:34:59 UTC
Last enriched: 09/11/2026, 09:48:56 UTC
Last updated: 10/03/2026, 02:46:03 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.