Code Injection Vulnerability in Crocoblock JetEngine Plugin
CVE-2026-28134
8.5HIGH
What is CVE-2026-28134?
An improper control of code generation vulnerability has been identified in the Crocoblock JetEngine plugin, allowing attackers to execute remote code inclusion. This issue impacts versions up to 3.7.2, posing significant risks for WordPress sites utilizing the plugin. When exploited, this vulnerability can enable malicious user-controlled code to be executed on the server, leading to unauthorized access and potential compromise of the entire web application.
Affected Version(s)
JetEngine 0 <= 3.7.2