All verified exploits

CVE-2026-4662 Unauthenticated SQL Injection via JetEngine Listing AJAX Handler

Deterministic high WordPress Added cve-verified-cve-2026-4662

Detects WordPress installs running the JetEngine plugin at version 3.8.6.1 or earlier. The listing_load_more AJAX handler excludes filtered_query from HMAC validation, and the SQL Query Builder's prepare_where_clause() concatenates user-controlled compare operators into SQL without sanitization. An unauthenticated attacker can extract database contents including usernames and password hashes. Update to JetEngine 3.8.6.2 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-4662?

Scan your domain free