{"id":"CVE-2026-14864","title":"The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that exe…","summary":"The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that exe…","severity":"none","published":"2026-08-02","updated":"2026-08-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14864","references":[{"url":"https://wpscan.com/vulnerability/7222601e-4f2b-4dfb-88aa-692a556f3e86/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-02T09:18:12.311Z","epss":0.00129,"epssPercentile":0.02921,"slug":"CVE-2026-14864","body":"## Overview\n\nThe JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}