Unauthenticated SQL Injection in JetEngine Plugin by Crocoblock
CVE-2026-54187
9.3CRITICAL
What is CVE-2026-54187?
An unauthenticated SQL Injection vulnerability exists in the JetEngine plugin versions up to 3.8.10.1. This flaw allows malicious actors to execute arbitrary SQL queries, potentially leading to unauthorized data disclosure or manipulation. Users of affected versions should take immediate action to update their JetEngine plugin to mitigate this risk and secure their WordPress installations.
Affected Version(s)
JetEngine <= 3.8.10.1