CVE · High

CVE-2026-28134 — JetEngine [jet-engine] < 3.8.1.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-28134 JetEngine [jet-engine] < 3.8.1.2 Improper Control of Generation of Code ('Code Injection') High 8.5 < 3.8.1.2 3.8.1.2 2026-02-26

CVE-2026-28134

A security flaw exists within the JetEngine plugin for WordPress, allowing malicious users with elevated permissions to inject arbitrary commands on the server, effective in versions prior to 3.7.2. This vulnerability can be exploited by authenticated attackers possessing at least Contributor-level access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.