Template Engine Code Injection Vulnerability in JetEngine from Crocoblock
CVE-2025-53194

8.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
20 August 2025

What is CVE-2025-53194?

A vulnerability in Crocoblock's JetEngine allows for code injection due to inadequate handling of special elements used in the template engine. This issue affects versions from n/a up to 3.7.0, potentially allowing attackers to execute arbitrary code within the application, posing significant security risks.

Affected Version(s)

JetEngine <= 3.7.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.