PHP Object Injection Vulnerability in JetEngine Plugin by Crocoblock
CVE-2026-52706
9.8CRITICAL
What is CVE-2026-52706?
An unauthenticated PHP Object Injection vulnerability exists in the JetEngine plugin for WordPress, specifically affecting versions up to 3.8.10. This security flaw allows unauthenticated attackers to exploit the injection, potentially leading to unauthorized access and manipulation of sensitive data. It is crucial for users of the affected versions to apply updates and mitigate risks associated with this vulnerability.
Affected Version(s)
JetEngine <= 3.8.10