Unauthenticated Cross Site Scripting Vulnerability in JetEngine Plugin by Crocoblock
CVE-2026-54188
7.1HIGH
What is CVE-2026-54188?
An unauthenticated Cross Site Scripting (XSS) vulnerability in JetEngine versions prior to 3.8.10 allows attackers to inject malicious scripts into web pages viewed by users. This can lead to unauthorized data access and exploitation of users' sessions. Website administrators using JetEngine are advised to update to the latest version to mitigate the risk.
Affected Version(s)
JetEngine <= 3.8.10