CVE-2025-53194 identifies a Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine plugin versions up to 3.7.0, which could lead to remote Code Injection. Rated 8.5 (High) on CVSS, this flaw has a network attack vector and requires low privileges but high attack complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While the vulnerability is significant, there is currently no public exploit code available in common databases like Metasploit or ExploitDB. Furthermore, it is not listed on CISA's Known Exploited Vulnerabilities catalog, and community discussion or media coverage remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 3.7.0CPE match | cpe:2.3:a:crocoblock:jetengine:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.