PLUGIN SECURITY
Is Jet Engine safe?
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
What this plugin does
- Slug:
jet-engine - Author: miniOrange
- 5000+ active installs
- 94/100 rating (438 reviews on wordpress.org)
- 475478 all-time downloads
- On WordPress.org since 2015-12-18
email verificationotpotp loginphone verificationsms notifications
Maintenance status
- Latest known version: 5.5.4
- Last updated: 2026-08-27 6:26am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.3.0+
Known vulnerabilities
38 known CVEs on file for Jet Engine.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-81760 | JetEngine [jet-engine] < 3.8.14.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.14.3 | 3.8.14.3 | 2026-08-21 | ✓ fixed in latest |
| CVE-2026-66581 | JetEngine [jet-engine] < 3.8.14.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.14.2 | 3.8.14.2 | 2026-08-20 | ✓ fixed in latest |
| CVE-2026-18202 | JetEngine [jet-engine] < 3.8.14 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 3.8.14 | 3.8.14 | 2026-08-19 | ✓ fixed in latest |
| CVE-2026-66613 | JetEngine [jet-engine] < 3.8.14.1 | Improper Neutralization of Special Elements Used in a Template Engine | Critical 9.8 | < 3.8.14.1 | 3.8.14.1 | 2026-08-19 | ✓ fixed in latest |
| CVE-2026-17019 | JetEngine [jet-engine] < 3.8.13.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 3.8.13.1 | 3.8.13.1 | 2026-08-05 | ✓ fixed in latest |
| CVE-2026-28082 | JetEngine [jet-engine] < 3.8.13.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.13.2 | 3.8.13.2 | 2026-08-03 | ✓ fixed in latest |
| CVE-2026-14864 | JetEngine [jet-engine] < 3.8.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 3.8.12 | 3.8.12 | 2026-08-02 | ✓ fixed in latest |
| CVE-2026-56068 | JetEngine [jet-engine] < 3.8.11 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 3.8.11 | 3.8.11 | 2026-06-25 | ✓ fixed in latest |
+ 34 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-12360 | JetEngine [jet-engine] < 3.8.10.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 3.8.10.2 | 3.8.10.2 | 2026-06-16 | ✓ fixed in latest |
| CVE-2026-54189 | JetEngine [jet-engine] < 3.8.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.10.1 | 3.8.10.1 | 2026-06-16 | ✓ fixed in latest |
| CVE-2026-54188 | JetEngine [jet-engine] < 3.8.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.10.1 | 3.8.10.1 | 2026-06-16 | ✓ fixed in latest |
| CVE-2026-54187 | JetEngine [jet-engine] < 3.8.10.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 3.8.10.2 | 3.8.10.2 | 2026-06-15 | ✓ fixed in latest |
| CVE-2026-52706 | JetEngine [jet-engine] < 3.8.10.1 | Deserialization of Untrusted Data | Critical 9.8 | < 3.8.10.1 | 3.8.10.1 | 2026-06-12 | ✓ fixed in latest |
| CVE-2026-49075 | JetEngine [jet-engine] < 3.8.10 | Deserialization of Untrusted Data | Critical 9.8 | < 3.8.10 | 3.8.10 | 2026-06-08 | ✓ fixed in latest |
| CVE-2026-49074 | JetEngine [jet-engine] < 3.8.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.10 | 3.8.10 | 2026-06-08 | ✓ fixed in latest |
| CVE-2026-49076 | JetEngine [jet-engine] < 3.8.10 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 3.8.10 | 3.8.10 | 2026-06-08 | ✓ fixed in latest |
| CVE-2026-49084 | JetEngine [jet-engine] < 3.8.9.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 3.8.9.1 | 3.8.9.1 | 2026-06-08 | ✓ fixed in latest |
| CVE-2026-42774 | JetEngine [jet-engine] < 3.8.8.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.3 | < 3.8.8.2 | 3.8.8.2 | 2026-04-30 | ✓ fixed in latest |
| CVE-2026-28134 | JetEngine [jet-engine] < 3.8.1.2 | Improper Control of Generation of Code ('Code Injection') | High 8.5 | < 3.8.1.2 | 3.8.1.2 | 2026-02-26 | ✓ fixed in latest |
| CVE-2026-32355 | JetEngine [jet-engine] < 3.8.4.1 | Deserialization of Untrusted Data | High 8.8 | < 3.8.4.1 | 3.8.4.1 | 2026-02-14 | ✓ fixed in latest |
| CVE-2025-68495 | JetEngine [jet-engine] < 3.8.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.8.1 | 3.8.1 | 2026-02-11 | ✓ fixed in latest |
| CVE-2025-67923 | JetEngine [jet-engine] < 3.7.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.7.8 | 3.7.8 | 2026-01-05 | ✓ fixed in latest |
| CVE-2025-69333 | JetEngine [jet-engine] < 3.8.1.2 | Missing Authorization | Unknown | < 3.8.1.2 | 3.8.1.2 | 2025-12-30 | ✓ fixed in latest |
| CVE-2025-49938 | JetEngine [jet-engine] < 3.7.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.7.4 | 3.7.4 | 2025-09-18 | ✓ fixed in latest |
| CVE-2025-54688 | JetEngine [jet-engine] < 3.7.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.7.2 | 3.7.2 | 2025-07-30 | ✓ fixed in latest |
| CVE-2025-53196 | JetEngine [jet-engine] < 3.7.1.1 | Insertion of Sensitive Information Into Sent Data | Medium 6.5 | < 3.7.1.1 | 3.7.1.1 | 2025-07-16 | ✓ fixed in latest |
| CVE-2025-53194 | JetEngine [jet-engine] < 3.7.1.1 | Improper Neutralization of Script in Attributes of IMG Tags in a Web Page | High 8.5 | < 3.7.1.1 | 3.7.1.1 | 2025-07-13 | ✓ fixed in latest |
| CVE-2025-53195 | JetEngine [jet-engine] < 3.7.1.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.7.1.1 | 3.7.1.1 | 2025-06-27 | ✓ fixed in latest |
| CVE-2025-26870 | JetEngine [jet-engine] < 3.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.6.5 | 3.6.5 | 2025-04-11 | ✓ fixed in latest |
| CVE-2023-48762 | JetEngine [jet-engine] < 3.2.5.2 | Cross-Site Request Forgery (CSRF) | Medium 6.3 | < 3.2.5.2 | 3.2.5.2 | 2023-11-28 | ✓ fixed in latest |
| CVE-2023-48761 | JetEngine [jet-engine] < 3.2.5.2 | Missing Authorization | Medium 6.3 | < 3.2.5.2 | 3.2.5.2 | 2023-11-28 | ✓ fixed in latest |
| CVE-2023-48758 | JetEngine [jet-engine] < 3.2.5 | Missing Authorization | High 7.1 | < 3.2.5 | 3.2.5 | 2023-11-28 | ✓ fixed in latest |
| CVE-2023-48757 | JetEngine [jet-engine] < 3.2.5 | Improper Privilege Management | High 8.8 | < 3.2.5 | 3.2.5 | 2023-11-28 | ✓ fixed in latest |
| CVE-2023-1406 | JetEngine [jet-engine] < 3.1.3.1 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 3.1.3.1 | 3.1.3.1 | 2023-03-20 | ✓ fixed in latest |
| — | JetEngine [jet-engine] < 3.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.6.3 | 3.6.3 | 0000-00-00 | ✓ fixed in latest |
| — | JetEngine [jet-engine] < 3.8.6.2 | — | Unknown | < 3.8.6.2 | 3.8.6.2 | 0000-00-00 | ✓ fixed in latest |
| — | JetEngine [jet-engine] < 3.8.6.2 | — | Unknown | < 3.8.6.2 | 3.8.6.2 | 0000-00-00 | ✓ fixed in latest |
| — | JetEngine [jet-engine] < 3.8.12 | — | Unknown | < 3.8.12 | 3.8.12 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-0369 | Jet Engine < 3.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter | — | Unknown | < 3.6.3 | 3.6.3 | — | ✓ fixed in latest |
| CVE-2026-4662 | JetEngine < 3.8.6.2 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter | — | Unknown | < 3.8.6.2 | 3.8.6.2 | — | ✓ fixed in latest |
| CVE-2026-4352 | JetEngine < 3.8.6.2 - Unauthenticated SQL Injection via '_cct_search' Parameter | — | Unknown | < 3.8.6.2 | 3.8.6.2 | — | ✓ fixed in latest |
| CVE-2026-65467 | JetEngine < 3.8.12 - Authenticated (Contributor+) Sever-Side Request Forgery | — | Unknown | < 3.8.12 | 3.8.12 | — | ✓ fixed in latest |
How to fix it
Keep Jet Engine updated — 5.5.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Google Authenticator — 20000+ active installs — 86/100 (135) — max PHP 8.4
- Customer Email Verification for WooCommerce — 8000+ active installs — 96/100 (47) — max PHP 8.4
- Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification — 1000+ active installs — 100/100 (9) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.