Junglewise Threat Intelligence

CVE-2026-65467: Crocoblock JetEngine SSRF in WordPress plugin

CVE-2026-65467 · Severity: medium · CVSS 4.9 · Published 2026-07-23

Technologies: Crocoblock (Jetimpex Inc.) JetEngine. Vendors: Crocoblock.

Executive brief

JetEngine is a popular WordPress plugin used for creating dynamic content and custom website structures. A security flaw allows users with 'Contributor' level access to force the website to make unauthorized requests to internal or external servers. This could lead to the exposure of sensitive information from other services running on the same network or the internal system.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the JetEngine plugin for WordPress (versions <= 3.8.11). The flaw is classified under CWE-918 and stems from insufficient validation of user-supplied URLs, allowing an attacker with Contributor-level privileges to cause the server to execute requests to arbitrary domains. While the attack complexity is rated as high, a successful exploit could allow an attacker to probe internal network services or access sensitive metadata that is otherwise unreachable from the public internet. The issue is resolved in version 3.8.12.

Affected products

  • Crocoblock (Jetimpex Inc.) JetEngine <= 3.8.11

Timeline

  • 2026-07-02: other: Reported by researcher Ananda Dhakal
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-22: patched: Fixed in version 3.8.12

References

Related threats