Executive brief
JetEngine is a popular WordPress plugin used for creating dynamic content and custom website structures. A critical security flaw allows unauthenticated attackers to inject malicious code into the website. If exploited, this could lead to a total takeover of the site, theft of customer data, or a complete service outage.
Technical details
A PHP Object Injection vulnerability exists in the JetEngine plugin for WordPress due to the insecure deserialization of user-supplied data. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker can achieve remote code execution, SQL injection, or file system traversal. The vulnerability is fixed in version 3.8.10.1.
Affected products
- Jetimpex Inc. JetEngine <= 3.8.10
Timeline
- 2026-06-08: other: Reported by researcher VanTastic
- 2026-06-12: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date
- 2026-06-17: patched: Patch confirmed available in version 3.8.10.1