Executive brief
JetEngine, a popular WordPress plugin used for building dynamic content structures, contains a critical security flaw. An unauthenticated attacker can remotely interact with the website's database, potentially leading to the theft of sensitive customer data or administrative information. This type of vulnerability is frequently targeted in automated mass-exploitation campaigns against WordPress sites.
Technical details
A critical SQL injection vulnerability exists in the JetEngine plugin for WordPress due to improper neutralization of special elements used in an SQL command (CWE-89). The flaw allows an unauthenticated remote attacker to send specially crafted requests to the server to execute arbitrary SQL queries against the backend database. This can result in the unauthorized retrieval of sensitive information, such as user credentials or site configuration data. The vulnerability is present in versions up to and including 3.8.9.1 and has been addressed in version 3.8.10.
Affected products
- Jetimpex Inc. (Crocoblock) JetEngine <= 3.8.9.1
Timeline
- 2026-05-19: other: Reported by researcher daroo
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD
- 2026-06-17: patched: Fixed in version 3.8.10