CyberRota Analysis
AI-GeneratedThe JetEngine WordPress plugin prior to version 3.8.13.1 is vulnerable due to insufficient sanitization of uploaded SVG files and inadequate access controls for file uploads. This flaw allows unauthenticated attackers to upload malicious JavaScript, leading to Stored Cross-Site Scripting (XSS) that executes in the browsers of users accessing the affected site. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).