What is CVE-2026-18202?
CVE-2026-18202 is a security vulnerability in the JetEngine WordPress plugin versions prior to 3.8.14. The plugin allows SVG uploads for users with file-upload capabilities like Authors, but fails to sanitize file contents, enabling stored cross-site scripting (XSS) attacks. Malicious JavaScript embedded in an SVG file executes in the browser of anyone viewing it, posing risks such as session hijacking; immediate update to the latest plugin version is required.
Azərbaycanca: CVE-2026-18202 JetEngine WordPress plaginində, 3.8.14 versiyasından əvvəlki versiyalarda mövcud olan təhlükəsizlik boşluğudur. Plagin SVG fayllarının yüklənməsinə icazə verir, lakin məzmunu təmizləmədiyi üçün Author rolu kimi fayl yükləmə icazəsi olan istifadəçilər zərərli JavaScript kodu yerləşdirə bilər. Bu kod, yüklənmiş fayla baxan istənilən istifadəçinin brauzerində icra olunaraq hesabın ələ keçirilməsi kimi risklər yarada bilər; təcili olaraq plugin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which JetEngine WordPress plugin versions are affected by CVE-2026-18202?
CVE-2026-18202 affects JetEngine plugin versions prior to 3.8.14.
What privilege level is required to exploit CVE-2026-18202?
Exploiting the vulnerability requires user privileges with file-upload capabilities, such as the Author role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.