What is CVE-2026-14864?
CVE-2026-14864 is a Stored XSS vulnerability in the JetEngine WordPress plugin before version 3.8.12. The plugin does not escape a post meta value before outputting it via a shortcode, allowing users with Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users like admins. Update the plugin to version 3.8.12 or later to mitigate this.
Azərbaycanca: CVE-2026-14864, 3.8.12-dən əvvəlki JetEngine WordPress plaginində saxlanılan XSS zəifliyidir. Plagin qısa kod vasitəsilə post meta dəyərini düzgün escape etmir, bu da Contributor və yuxarı rollu istifadəçilərə administratorlar kimi yüksək səlahiyyətli istifadəçilər kontekstində işləyən Stored XSS hücumları həyata keçirməyə imkan verir. Plagini ən az 3.8.12 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-14864?
CVE-2026-14864 is a Stored XSS vulnerability found in the JetEngine plugin prior to version 3.8.12.
What user roles can carry out this Stored XSS attack?
Users with Contributor role and above can perform this Stored Cross-Site Scripting attack in the context of higher-privileged users like admins.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.