The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.
History

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.
Title JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T06:00:18.765Z

Reserved: 2026-07-29T07:47:33.859Z

Link: CVE-2026-18202

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T06:17:37.163

Modified: 2026-08-19T06:17:37.163

Link: CVE-2026-18202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.