AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17019

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The JetEngine WordPress plugin prior to version 3.8.13.1 is vulnerable due to insufficient sanitization of uploaded SVG files and inadequate access controls for file uploads. This flaw allows unauthenticated attackers to upload malicious JavaScript, leading to Stored Cross-Site Scripting (XSS) that executes in the browsers of users accessing the affected site. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-17019
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
WordPress Java

Original NVD Description

The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).