PLUGIN SECURITY

Is Jet Engine safe?

OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification

What this plugin does

  • Slug: jet-engine
  • Author: miniOrange
  • 5000+ active installs
  • 94/100 rating (438 reviews on wordpress.org)
  • 475478 all-time downloads
  • On WordPress.org since 2015-12-18

email verificationotpotp loginphone verificationsms notifications

Maintenance status

  • Latest known version: 5.5.4
  • Last updated: 2026-08-27 6:26am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.3.0+

Known vulnerabilities

38 known CVEs on file for Jet Engine.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-81760 JetEngine [jet-engine] < 3.8.14.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.14.3 3.8.14.3 2026-08-21 ✓ fixed in latest
CVE-2026-66581 JetEngine [jet-engine] < 3.8.14.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.14.2 3.8.14.2 2026-08-20 ✓ fixed in latest
CVE-2026-18202 JetEngine [jet-engine] < 3.8.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.8.14 3.8.14 2026-08-19 ✓ fixed in latest
CVE-2026-66613 JetEngine [jet-engine] < 3.8.14.1 Improper Neutralization of Special Elements Used in a Template Engine Critical 9.8 < 3.8.14.1 3.8.14.1 2026-08-19 ✓ fixed in latest
CVE-2026-17019 JetEngine [jet-engine] < 3.8.13.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.8.13.1 3.8.13.1 2026-08-05 ✓ fixed in latest
CVE-2026-28082 JetEngine [jet-engine] < 3.8.13.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.13.2 3.8.13.2 2026-08-03 ✓ fixed in latest
CVE-2026-14864 JetEngine [jet-engine] < 3.8.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.8.12 3.8.12 2026-08-02 ✓ fixed in latest
CVE-2026-56068 JetEngine [jet-engine] < 3.8.11 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.8.11 3.8.11 2026-06-25 ✓ fixed in latest
+ 34 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12360 JetEngine [jet-engine] < 3.8.10.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 3.8.10.2 3.8.10.2 2026-06-16 ✓ fixed in latest
CVE-2026-54189 JetEngine [jet-engine] < 3.8.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.10.1 3.8.10.1 2026-06-16 ✓ fixed in latest
CVE-2026-54188 JetEngine [jet-engine] < 3.8.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.10.1 3.8.10.1 2026-06-16 ✓ fixed in latest
CVE-2026-54187 JetEngine [jet-engine] < 3.8.10.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.8.10.2 3.8.10.2 2026-06-15 ✓ fixed in latest
CVE-2026-52706 JetEngine [jet-engine] < 3.8.10.1 Deserialization of Untrusted Data Critical 9.8 < 3.8.10.1 3.8.10.1 2026-06-12 ✓ fixed in latest
CVE-2026-49075 JetEngine [jet-engine] < 3.8.10 Deserialization of Untrusted Data Critical 9.8 < 3.8.10 3.8.10 2026-06-08 ✓ fixed in latest
CVE-2026-49074 JetEngine [jet-engine] < 3.8.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.10 3.8.10 2026-06-08 ✓ fixed in latest
CVE-2026-49076 JetEngine [jet-engine] < 3.8.10 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.8.10 3.8.10 2026-06-08 ✓ fixed in latest
CVE-2026-49084 JetEngine [jet-engine] < 3.8.9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.8.9.1 3.8.9.1 2026-06-08 ✓ fixed in latest
CVE-2026-42774 JetEngine [jet-engine] < 3.8.8.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 3.8.8.2 3.8.8.2 2026-04-30 ✓ fixed in latest
CVE-2026-28134 JetEngine [jet-engine] < 3.8.1.2 Improper Control of Generation of Code ('Code Injection') High 8.5 < 3.8.1.2 3.8.1.2 2026-02-26 ✓ fixed in latest
CVE-2026-32355 JetEngine [jet-engine] < 3.8.4.1 Deserialization of Untrusted Data High 8.8 < 3.8.4.1 3.8.4.1 2026-02-14 ✓ fixed in latest
CVE-2025-68495 JetEngine [jet-engine] < 3.8.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.8.1 3.8.1 2026-02-11 ✓ fixed in latest
CVE-2025-67923 JetEngine [jet-engine] < 3.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.7.8 3.7.8 2026-01-05 ✓ fixed in latest
CVE-2025-69333 JetEngine [jet-engine] < 3.8.1.2 Missing Authorization Unknown < 3.8.1.2 3.8.1.2 2025-12-30 ✓ fixed in latest
CVE-2025-49938 JetEngine [jet-engine] < 3.7.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.7.4 3.7.4 2025-09-18 ✓ fixed in latest
CVE-2025-54688 JetEngine [jet-engine] < 3.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.7.2 3.7.2 2025-07-30 ✓ fixed in latest
CVE-2025-53196 JetEngine [jet-engine] < 3.7.1.1 Insertion of Sensitive Information Into Sent Data Medium 6.5 < 3.7.1.1 3.7.1.1 2025-07-16 ✓ fixed in latest
CVE-2025-53194 JetEngine [jet-engine] < 3.7.1.1 Improper Neutralization of Script in Attributes of IMG Tags in a Web Page High 8.5 < 3.7.1.1 3.7.1.1 2025-07-13 ✓ fixed in latest
CVE-2025-53195 JetEngine [jet-engine] < 3.7.1.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.7.1.1 3.7.1.1 2025-06-27 ✓ fixed in latest
CVE-2025-26870 JetEngine [jet-engine] < 3.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.6.5 3.6.5 2025-04-11 ✓ fixed in latest
CVE-2023-48762 JetEngine [jet-engine] < 3.2.5.2 Cross-Site Request Forgery (CSRF) Medium 6.3 < 3.2.5.2 3.2.5.2 2023-11-28 ✓ fixed in latest
CVE-2023-48761 JetEngine [jet-engine] < 3.2.5.2 Missing Authorization Medium 6.3 < 3.2.5.2 3.2.5.2 2023-11-28 ✓ fixed in latest
CVE-2023-48758 JetEngine [jet-engine] < 3.2.5 Missing Authorization High 7.1 < 3.2.5 3.2.5 2023-11-28 ✓ fixed in latest
CVE-2023-48757 JetEngine [jet-engine] < 3.2.5 Improper Privilege Management High 8.8 < 3.2.5 3.2.5 2023-11-28 ✓ fixed in latest
CVE-2023-1406 JetEngine [jet-engine] < 3.1.3.1 Unrestricted Upload of File with Dangerous Type High 8.8 < 3.1.3.1 3.1.3.1 2023-03-20 ✓ fixed in latest
JetEngine [jet-engine] < 3.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.6.3 3.6.3 0000-00-00 ✓ fixed in latest
JetEngine [jet-engine] < 3.8.6.2 Unknown < 3.8.6.2 3.8.6.2 0000-00-00 ✓ fixed in latest
JetEngine [jet-engine] < 3.8.6.2 Unknown < 3.8.6.2 3.8.6.2 0000-00-00 ✓ fixed in latest
JetEngine [jet-engine] < 3.8.12 Unknown < 3.8.12 3.8.12 0000-00-00 ✓ fixed in latest
CVE-2025-0369 Jet Engine < 3.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter Unknown < 3.6.3 3.6.3 ✓ fixed in latest
CVE-2026-4662 JetEngine < 3.8.6.2 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter Unknown < 3.8.6.2 3.8.6.2 ✓ fixed in latest
CVE-2026-4352 JetEngine < 3.8.6.2 - Unauthenticated SQL Injection via '_cct_search' Parameter Unknown < 3.8.6.2 3.8.6.2 ✓ fixed in latest
CVE-2026-65467 JetEngine < 3.8.12 - Authenticated (Contributor+) Sever-Side Request Forgery Unknown < 3.8.12 3.8.12 ✓ fixed in latest

How to fix it

Keep Jet Engine updated — 5.5.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.