Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.
Published: 2026-06-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch
AI Analysis

Impact

The Crocoblock JetEngine plugin for WordPress up to version 3.8.9.1 contains an improper neutralization of special elements in SQL statements, resulting in a blind SQL injection flaw. An attacker can inject crafted SQL into plugin queries and read or modify data stored in the database. If the database user has high privileges, the attacker can gain full control over the application database, leading to data loss, theft, or site compromise. This vulnerability is classified as CWE‑89 and has a CVSS score of 9.3, indicating a high probability of severe impact.

Affected Systems

The affected product is the Crocoblock JetEngine plugin for WordPress. All installations running any version of JetEngine up to and including 3.8.9.1 are vulnerable; newer releases are not impacted.

Risk and Exploitability

The CVSS score of 9.3 reflects critical risk, while the EPSS score of less than 1% (0.004) indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation via crafted requests to the plugin’s endpoints without authentication, a scenario inferred from the description of blind SQL injection. Attackers can exploit it remotely by sending such crafted requests during normal web traffic, making it easily exploitable.

Generated by OpenCVE AI on September 28, 2026 at 08:22 UTC.

Remediation

Vendor Solution

Update the WordPress JetEngine plugin to the latest available version (at least 3.8.10).


OpenCVE Recommended Actions

  • Upgrade the JetEngine plugin to version 3.8.10 or later.
  • If the plugin is not required, remove or disable it from the WordPress installation.
  • Apply the principle of least privilege to the database user(s) used by WordPress; restrict them to the minimal permissions needed for normal operation.
  • Monitor web and database logs for anomalous SQL activity to detect potential exploitation attempts.

Generated by OpenCVE AI on September 28, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.

Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetimpex Inc.
Jetimpex Inc. jetengine
Wordpress
Wordpress wordpress
Vendors & Products Jetimpex Inc.
Jetimpex Inc. jetengine
Wordpress
Wordpress wordpress

Wed, 17 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.
Title WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Jetimpex Inc. Jetengine
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-28T05:53:19.587Z

Reserved: 2026-05-27T10:27:01.186Z

Link: CVE-2026-49076

cve-icon Vulnrichment

Updated: 2026-06-17T13:37:32.509Z

cve-icon NVD

Status : Deferred

Published: 2026-06-17T13:20:45.790

Modified: 2026-09-28T06:16:31.777

Link: CVE-2026-49076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T08:30:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')