Executive brief
JetEngine, a popular WordPress plugin used for creating dynamic content and custom site structures, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer data, administrative credentials, or other private information stored on the site.
Technical details
JetEngine versions 3.8.10.1 and below are vulnerable to an unauthenticated SQL injection (CWE-89). The vulnerability exists due to improper neutralization of special elements used in an SQL command, allowing a remote attacker to send specially crafted queries to the database. Because the flaw is reachable without authentication, an attacker can bypass security controls to extract sensitive information or potentially impact database availability. The issue is resolved in version 3.8.10.2.
Affected products
- Jetimpex Inc. (Crocoblock) JetEngine <= 3.8.10.1
Timeline
- 2026-06-08: other: Reported by researcher VanTastic
- 2026-06-15: disclosed: Vulnerability disclosed by Patchstack
- 2026-06-17: advisory: CVE published to NVD
- 2026-06-17: patched: Patch confirmed available in version 3.8.10.2