
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4662 is an unauthenticated SQL Injection vulnerability in the JetEngine plugin for WordPress, affecting all versions up to and including 3.8.6.1. The flaw resides in the listing_load_more AJAX action and allows unauthenticated remote attackers to extract sensitive information from the database. It was published on March 24, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, ENISA EUVD).
The vulnerability (CWE-89: SQL Injection) arises from two compounding weaknesses: the filtered_query parameter is excluded from HMAC signature validation, allowing attacker-controlled input to bypass security checks; and the prepare_where_clause() method in the SQL Query Builder does not sanitize the compare operator before concatenating it into SQL statements. This combination enables an unauthenticated attacker to append arbitrary SQL to existing queries via the listing_load_more AJAX endpoint. Exploitation requires the target site to have a JetEngine Listing Grid with "Load More" enabled that uses a SQL Query Builder query (Wordfence, WordPress Plugin Trac).
Successful exploitation allows unauthenticated attackers to extract sensitive information from the WordPress database, potentially including user credentials, personal data, API keys, and other confidential content stored in the database. The vulnerability has a high confidentiality impact with no integrity or availability impact, meaning attackers can read but not directly modify or destroy data through this vector alone. Extracted credentials could, however, enable further compromise such as administrative account takeover and lateral movement within the hosting environment (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.079%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated, network-accessible nature of the flaw with no user interaction required makes it an attractive target if a PoC is published (Wordfence, ENISA EUVD).
listing_load_more WordPress AJAX action, typically accessible via wp-admin/admin-ajax.php?action=listing_load_more (or the nopriv equivalent for unauthenticated access).filtered_query parameter containing a malicious compare operator value (e.g., = 1 OR 1=1 --) that is not covered by HMAC signature validation.compare operator is concatenated directly into the SQL WHERE clause by prepare_where_clause(), executing the injected SQL against the database.wp-admin/admin-ajax.php with action=listing_load_more containing anomalous or encoded filtered_query parameter values; requests from unexpected IP ranges with no prior site interaction.admin-ajax.php?action=listing_load_more with varying compare operator values or SQL metacharacters (e.g., ', --, OR, UNION) in POST body parameters.Users should update the JetEngine plugin to version 3.8.7 or later, which addresses this vulnerability (Crocoblock Changelog). As an interim workaround, administrators can disable the "Load More" feature on any Listing Grid that uses a SQL Query Builder query until the patch is applied. Web application firewalls (WAFs) with SQL injection rules can provide an additional layer of defense. Regularly auditing installed plugin versions and enabling automatic updates for security releases is strongly recommended (Wordfence).
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for the week of March 23–29, 2026, highlighting it as a notable unauthenticated SQL injection risk (Wordfence Blog). The vulnerability was also picked up by RedPacket Security and shared on social media shortly after disclosure (RedPacket Security). General community reaction reflects standard concern for unauthenticated SQL injection flaws in widely-used WordPress plugins.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."