Junglewise Threat Intelligence

CVE-2026-49075: Jetimpex JetEngine PHP Object Injection

CVE-2026-49075 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Crocoblock JetEngine. Vendors: Crocoblock.

Executive brief

JetEngine is a popular WordPress plugin used to create and manage dynamic content structures. A security flaw in this plugin allows an attacker to inject malicious code into the website. If exploited, this could lead to a full site takeover, theft of sensitive customer data, or a complete service outage.

Technical details

A PHP Object Injection vulnerability exists in JetEngine versions up to and including 3.8.9.1 due to improper deserialization of untrusted data. Although the advisory title mentions 'Contributor' level, the provided CVSS vector (PR:N) and Patchstack details suggest the flaw may be exploitable without high-level authentication if a suitable POP chain is present. An attacker can leverage this to achieve remote code execution, SQL injection, or path traversal. The issue is resolved in version 3.8.10.

Affected products

  • Jetimpex Inc. (Crocoblock) JetEngine <= 3.8.9.1

Timeline

  • 2026-05-19: other: Reported by researcher daroo
  • 2026-06-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date
  • 2026-06-17: patched: Patch confirmed available in version 3.8.10

References

Related threats