SQL Injection Vulnerability in JetEngine Plugin for WordPress
CVE-2026-12360
7.5HIGH
What is CVE-2026-12360?
The JetEngine plugin for WordPress, up to version 3.8.10.1, contains a vulnerability that allows SQL injection through the listing_load_more AJAX handler. This endpoint accepts a filtered_query parameter that is not properly validated, permitting attackers to inject harmful meta_query values. As a result, unauthorized users can exploit this flaw to execute time-based or boolean blind SQL injections via public Listing Grid pages.
Affected Version(s)
JetEngine 0 <= 3.8.10.1