Executive brief
JetEngine is a popular WordPress plugin used for creating and managing dynamic content and custom post types. A security flaw allows unauthenticated attackers to interact directly with the website's database, potentially leading to the theft of sensitive information or disruption of site operations. This vulnerability is considered high priority as it can be exploited remotely without any user interaction or login credentials.
Technical details
A SQL injection vulnerability exists in the JetEngine plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an unauthenticated remote attacker to send specially crafted requests to the server to execute arbitrary SQL queries. This can lead to unauthorized data retrieval from the database or partial service disruption. The vulnerability affects all versions up to and including 3.8.10.2 and has been addressed in version 3.8.11.
Affected products
- Crocoblock (Jetimpex Inc.) JetEngine <= 3.8.10.2
Timeline
- 2026-06-17: other: Reported by Rafie Muhammad
- 2026-06-25: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date
- 2026-06-26: patched: Version 3.8.11 released to address the issue