Cross-Site Scripting
10 records32.3%First: 2025. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 31 vulnerability records associated with JetEngine, published between 2023 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 5 | |
| 2025 | 8 | |
| 2026 | 18 |
| Severity | Records | Share |
|---|---|---|
| High | 20 | 64.5% |
| Medium | 11 | 35.5% |
First: 2025. Latest: 2026.
First: 2026. Latest: 2026.
First: 2025. Latest: 2026.
First: 2023. Latest: 2025.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.8.123.8.113.8.10.13.8.10.23.8.103.8.9.13.8.8.23.8.6.23.8.4.13.8.13.7.83.8.1.23.7.43.7.23.7.1.13.6.53.6.33.2.53.2.5.23.1.3.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.6.2 | Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter | January 17, 2025 | 3.6.3 | Medium |
*-3.2.4 | JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation | November 28, 2023 | 3.2.5 | High |
*-3.2.5.1 | Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization | November 28, 2023 | 3.2.5.2 | Medium |
*-3.2.4 | JetEngine <= 3.2.4 - Missing Authorization | November 28, 2023 | 3.2.5 | High |
*-3.2.5.1 | Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery | November 28, 2023 | 3.2.5.2 | Medium |
*-3.1.3 | Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution | March 20, 2023 | 3.1.3.1 | High |
Selected source records
Published: July 22, 2026
Published: June 25, 2026
Published: June 16, 2026
Published: June 16, 2026
Published: June 16, 2026
Published: June 15, 2026
Published: June 12, 2026
Published: June 8, 2026
Published: February 26, 2026
Published: November 28, 2023
Published: March 20, 2023
Published: June 12, 2026
Published: June 25, 2026
Published: April 13, 2026
Published: June 15, 2026
Published: June 8, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.