What is CVE-2026-17019?
CVE-2026-17019 is a vulnerability in the JetEngine WordPress plugin before version 3.8.13.1. It allows unauthenticated attackers to upload unsanitized SVG files containing malicious JavaScript, which then executes in the browsers of other users. It is recommended to immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-17019, JetEngine WordPress plaqininin 3.8.13.1-dən əvvəlki versiyalarında aşkarlanmış boşluqdur. Bu boşluq autentifikasiya olunmamış hücumçulara təmizlənməmiş, zərərli JavaScript ehtiva edən SVG faylları yükləməyə imkan verir və bu fayllar digər istifadəçilərin brauzerində icra olunur. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What can an attacker achieve by exploiting CVE-2026-17019?
This vulnerability allows unauthenticated attackers to upload unsanitized SVG files containing malicious JavaScript, which then executes in the browsers of other users.
Which versions of the JetEngine plugin are vulnerable to CVE-2026-17019?
Versions of the JetEngine plugin before 3.8.13.1 are vulnerable to this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.