CVE-2026-4352Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of `$wpdb->prepare()`. WordPress REST API's `wp_unslash()` call on `$_GET` strips the `wp_magic_quotes()` protection, allowing single-quote-based injection. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The Custom Content Types module must be enabled with at least one CCT configured with a public REST GET endpoint for exploitation.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-14: 304-1404-1504-17
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-143
Disclosure3
2026-04-151
General1
2026-04-171
PoC1
Full discourse5 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4352-jet-engine-version-3-8-6-1-high-vulnerability-proof-of-concept CVE-2026-4352 #WordPress plugin #vulnerability jet-engine #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The tweet announces a proof‑of‑concept for CVE‑2026‑4352 against Jet Engine 3.8.6.1, but offers no detailed technical info, patch guidance, or evidence of active exploitation.

    0000037
    7 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4352 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4352 #CVE-2026-4352 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/nIkM5cxpM5

    Post summary

    A brief alert announcing CVE-2026-4352 with a high severity rating for WordPress, but lacking any detailed technical, exploit, or mitigation information.

    0000031
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4352 The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6… https://www.cve.org/CVERecord?id=CVE-2026-4352

    Post summary

    The JetEngine WordPress plugin is vulnerable to SQL injection through its CCT REST API search endpoint. The post provides technical details but no evidence of exploitation or mitigation.

    0000061
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4352 SQL Injection in JetEngine Plugin for WordPress Versions Up to 3.8.6.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4352

    Post summary

    The text announces an SQL injection flaw in JetEngine Plugin (versions up to 3.8.6.1) but offers no PoC, exploit details, patched status, or active exploitation evidence.

    0000024
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-4352 The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search end… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-4352 #WordPress #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑4352 is a SQL Injection flaw in the JetEngine plugin’s CCT REST API for WordPress, rated CVSS 7.5, as announced by the vendor disclosure.

    000000
    144 followersView on X

Explore more