CVE-2026-4662Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks) combined with the `prepare_where_clause()` method in the SQL Query Builder not sanitizing the `compare` operator before concatenating it into SQL statements. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, provided the site has a JetEngine Listing Grid with Load More enabled that uses a SQL Query Builder query.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-24: 3Technical Details · 2026-03-24: 203-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4662 - Crocoblock - JetEngine - https://www.redpacketsecurity.com/cve-alert-cve-2026-4662-crocoblock-jetengine/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4662 #crocoblock #jetengine

    Post summary

    The post announces a CVE alert for SpoC Blaze, pointing to an external link for details, but provides no technical or exploit information.

    00000125
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4662 The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to … https://www.cve.org/CVERecord?id=CVE-2026-4662

    Post summary

    The JetEngine WordPress plugin suffers a SQL Injection vulnerability through the listing_load_more AJAX action in all versions up to 3.8.6.1. The CVE record documents the affected versions and the nature of the flaw.

    0000078
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4662 SQL Injection in JetEngine WordPress Plugin via Unauthenticated AJAX Acti... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4662 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A short tweet announces CVE‑2026‑4662, describing it as an unauthenticated AJAX‑based SQL injection in the JetEngine WordPress plugin and links to detail and notification pages.

    0000041
    4.0K followersView on X

Explore more