---
id: CVE-2026-14864
title: >-
  The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value
  before outputting it through one of its shortcodes, allowing users with the
  Contributor role and above to perform Stored Cross-Site Scripting attacks that
  exe…
summary: >-
  The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value
  before outputting it through one of its shortcodes, allowing users with the
  Contributor role and above to perform Stored Cross-Site Scripting attacks that
  exe…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14864'
references:
  - url: 'https://wpscan.com/vulnerability/7222601e-4f2b-4dfb-88aa-692a556f3e86/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T09:18:12.311Z'
epss: 0.00129
epssPercentile: 0.02913
---

## Overview

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
