Junglewise Threat Intelligence

CVE-2026-42774: Crocoblock JetEngine SQL injection

CVE-2026-42774 · Severity: critical · CVSS 9.3 · Published 2026-05-25

Technologies: Crocoblock JetEngine. Vendors: Crocoblock.

Executive brief

Crocoblock JetEngine, a popular WordPress plugin used for building dynamic content and websites, contains a critical security flaw that allows attackers to interact directly with the site's database. An unauthenticated attacker can exploit this to steal sensitive information, such as customer data or administrative credentials, potentially leading to a full site takeover. This vulnerability is considered high priority as it can be used in automated mass-exploitation campaigns against thousands of websites.

Technical details

A SQL injection vulnerability exists in the Crocoblock JetEngine plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 3.8.8.1. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted network requests to the affected site. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to the unauthorized extraction of sensitive information from the database or potential service disruption. The issue is resolved in version 3.8.8.2.

Affected products

  • Crocoblock JetEngine up to 3.8.8.1

Timeline

  • 2026-04-23: other: Reported by security researcher daroo
  • 2026-04-30: advisory: Initial Patchstack advisory published
  • 2026-05-25: disclosed: CVE-2026-42774 published to NVD
  • 2026-04-30: patched: Fixed in version 3.8.8.2

References

Related threats