Impact
The Crocoblock JetEngine plugin for WordPress up to version 3.8.9.1 contains an improper neutralization of special elements in SQL statements, resulting in a blind SQL injection flaw. An attacker can inject crafted SQL into plugin queries and read or modify data stored in the database. If the database user has high privileges, the attacker can gain full control over the application database, leading to data loss, theft, or site compromise. This vulnerability is classified as CWE‑89 and has a CVSS score of 9.3, indicating a high probability of severe impact.
Affected Systems
The affected product is the Crocoblock JetEngine plugin for WordPress. All installations running any version of JetEngine up to and including 3.8.9.1 are vulnerable; newer releases are not impacted.
Risk and Exploitability
The CVSS score of 9.3 reflects critical risk, while the EPSS score of less than 1% (0.004) indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation via crafted requests to the plugin’s endpoints without authentication, a scenario inferred from the description of blind SQL injection. Attackers can exploit it remotely by sending such crafted requests during normal web traffic, making it easily exploitable.
OpenCVE Enrichment