All 36 CVE vulnerabilities found in JetEngine, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities affecting JetEngine, a WordPress plugin that extends the capabilities of the Jetpack ecosystem by enabling custom post types and dynamic data handling. It collects reported security flaws ranging from cross-site scripting and privilege escalation to injection attacks, covering advisories published within the recent five-year window. Visitors can utilize this resource to monitor the specific security posture of the JetEngine plugin, analyze the frequency and severity of weaknesses in dynamic content generation tools, and review the historical pattern of patches issued by the developer. By examining this consolidated data, developers and security administrators gain insights into how common application logic errors manifest in WordPress extensions and can identify recurring themes in reported incidents. This collection serves as a reference point for understanding the evolution of security risks associated with third-party WordPress components, helping stakeholders assess the long-term stability and safety of systems relying on such plugins. The data is organized to facilitate clear analysis of vulnerability trends without requiring individual CVE lookups, providing a broader perspective on the product’s security lifecycle and the types of exploits most commonly targeted in its architecture.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-54688 | WordPress JetEngine Plugin plugin <= 3.7.1.2 - Cross Site Scripting (XSS) Vulnerability CWE-79 | 6.5 | Medium | 2025-08-14 |
| CVE-2025-26870 | WordPress JetEngine plugin <= 3.6.4.1 - Cross Site Scripting (XSS) vulnerability CWE-79 | 6.5 | Medium | 2025-04-15 |
| CVE-2025-0369 | Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter CWE-79 | 6.4 | Medium | 2025-01-18 |
| CVE-2023-48758 | WordPress JetEngine plugin <= 3.2.4 - Broken Access Control vulnerability CWE-862 | 7.1 | High | 2025-01-02 |
| CVE-2023-48757 | WordPress JetEngine plugin <= 3.2.4 - Privilege Escalation vulnerability CWE-269 | 8.8 | High | 2024-05-17 |
| CVE-2023-1406 | JetEngine < 3.1.3.1 - Author+ Remote Code Execution | 9.8 | - | 2023-04-10 |
All 36 known CVE vulnerabilities affecting JetEngine with full Chinese analysis, references, and POCs where available.