Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.
References
-
https://wpscan.com/vulnerability/7222601e-4f2b-4dfb-88aa-692a556f3e86/ technical-descriptionexploitvdb-entry
Affected products
JetEngine
- <3.8.12