Detects WordPress installs running the JetEngine plugin at version 3.8.6.1 or earlier. The listing_load_more AJAX handler excludes filtered_query from HMAC validation, and the SQL Query Builder's prepare_where_clause() concatenates user-controlled compare operators into SQL without sanitization. An unauthenticated attacker can extract database contents including usernames and password hashes. Update to JetEngine 3.8.6.2 or later.
Is your app exploitable through CVE-2026-4662?
Scan your domain free