CVE-2026-4662: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4662 is an unauthenticated SQL Injection vulnerability in the JetEngine plugin for WordPress, affecting all versions up to and including 3.8.6.1. The flaw resides in the listing_load_more AJAX action and allows unauthenticated remote attackers to extract sensitive information from the database. It was published on March 24, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, ENISA EUVD).

Technical details

The vulnerability (CWE-89: SQL Injection) arises from two compounding weaknesses: the filtered_query parameter is excluded from HMAC signature validation, allowing attacker-controlled input to bypass security checks; and the prepare_where_clause() method in the SQL Query Builder does not sanitize the compare operator before concatenating it into SQL statements. This combination enables an unauthenticated attacker to append arbitrary SQL to existing queries via the listing_load_more AJAX endpoint. Exploitation requires the target site to have a JetEngine Listing Grid with "Load More" enabled that uses a SQL Query Builder query (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, potentially including user credentials, personal data, API keys, and other confidential content stored in the database. The vulnerability has a high confidentiality impact with no integrity or availability impact, meaning attackers can read but not directly modify or destroy data through this vector alone. Extracted credentials could, however, enable further compromise such as administrative account takeover and lateral movement within the hosting environment (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.079%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated, network-accessible nature of the flaw with no user interaction required makes it an attractive target if a PoC is published (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running JetEngine ≤ 3.8.6.1 with a Listing Grid that has "Load More" enabled and uses a SQL Query Builder query. Tools like WPScan or Shodan can help enumerate plugin versions.
  2. Locate the vulnerable endpoint: Target the listing_load_more WordPress AJAX action, typically accessible via wp-admin/admin-ajax.php?action=listing_load_more (or the nopriv equivalent for unauthenticated access).
  3. Craft malicious payload: Construct a POST request that includes a manipulated filtered_query parameter containing a malicious compare operator value (e.g., = 1 OR 1=1 --) that is not covered by HMAC signature validation.
  4. Inject SQL: Submit the crafted request; the unsanitized compare operator is concatenated directly into the SQL WHERE clause by prepare_where_clause(), executing the injected SQL against the database.
  5. Extract data: Use time-based or error-based blind SQL injection techniques to enumerate database tables, extract WordPress user hashes, email addresses, or other sensitive data (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: Unusual or high-volume POST requests to wp-admin/admin-ajax.php with action=listing_load_more containing anomalous or encoded filtered_query parameter values; requests from unexpected IP ranges with no prior site interaction.
  • Logs: WordPress/web server access logs showing repeated AJAX requests to admin-ajax.php?action=listing_load_more with varying compare operator values or SQL metacharacters (e.g., ', --, OR, UNION) in POST body parameters.
  • Database: Unexpected or excessive database query load originating from the JetEngine SQL Query Builder; database error logs showing SQL syntax errors related to WHERE clause construction.
  • File System: No direct file system artifacts expected for a read-only SQL injection, but monitor for subsequent web shell uploads if attacker escalates access using extracted credentials.

Mitigation and workarounds

Users should update the JetEngine plugin to version 3.8.7 or later, which addresses this vulnerability (Crocoblock Changelog). As an interim workaround, administrators can disable the "Load More" feature on any Listing Grid that uses a SQL Query Builder query until the patch is applied. Web application firewalls (WAFs) with SQL injection rules can provide an additional layer of defense. Regularly auditing installed plugin versions and enabling automatic updates for security releases is strongly recommended (Wordfence).

Community reactions

Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for the week of March 23–29, 2026, highlighting it as a notable unauthenticated SQL injection risk (Wordfence Blog). The vulnerability was also picked up by RedPacket Security and shared on social media shortly after disclosure (RedPacket Security). General community reaction reflects standard concern for unauthenticated SQL injection flaws in widely-used WordPress plugins.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management