
🚨*CVE* CVE-2026-14864 The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor… https://www.cve.org/CVERecord?id=CVE-2026-14864 ----- Traducción: CVE-2026-14864 El … http://infoflow.cloud`
Post summary
The JetEngine WordPress plugin (prior to 3.8.12) contains a vulnerability where a post meta value is not properly escaped before being rendered via a shortcode, potentially enabling code or script injection; no PoC or active exploitation is mentioned.


