Executive brief
JetEngine is a popular WordPress plugin used for creating dynamic content and custom website structures. A security flaw allows unauthenticated attackers to perform SQL injection, which could lead to the theft of sensitive information from the website's database. This vulnerability is considered critical because it can be exploited remotely without any login credentials, potentially impacting site operations and data privacy.
Technical details
A SQL injection vulnerability exists in the JetEngine plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is reachable by unauthenticated users over the network, requiring no prior privileges or user interaction. An attacker can exploit this to execute arbitrary SQL queries, potentially leading to unauthorized data extraction or partial service disruption. The vulnerability is addressed in version 3.8.9.1.
Affected products
- Jetimpex Inc. (Crocoblock) JetEngine < 3.8.9.1
Timeline
- 2026-05-08: other: Reported by researcher Bonds
- 2026-06-08: disclosed: Vulnerability details published by Patchstack
- 2026-06-17: advisory: NVD published CVE-2026-49084