CVE · High

CVE-2026-28082 — JetEngine [jet-engine] < 3.8.13.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-28082 JetEngine [jet-engine] < 3.8.13.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.13.2 3.8.13.2 2026-08-03

CVE-2026-28082

A security flaw exists in JetEngine plugin versions up to 3.8.13.1, allowing malicious scripts to be injected into websites without user authentication. This vulnerability enables attackers to inject client-side code, potentially leading to unauthorized actions or data exposure.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.