CVE Feed

    Dashboard / CVE / CVE-2026-12360

    CVE-2026-12360

    The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values within filtered_query are not sanitized before being merged into SQL construction. This makes it possible for unauthenticated attackers to perform time-based or boolean blind SQL injection by appending a malicious meta_query value to a Load More AJAX request captured from any public Listing Grid page.

    Published:Jun 17, 2026
    Last Modified:Jun 17, 2026
    EPS:Jun 17, 2026
    EPSS Score:
    CVSS Score:7.5

    Affected Products

    Vendor
    Crocoblock
    Product
    Jetengine
    Vendor
    Wordpress
    Product
    Wordpress

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High