CVE-2026-4662 | Crocoblock JetEngine Plugin up to 3.8.6.1 on WordPress AJAX Action prepare_where_clause filtered_query sql injection
A vulnerability was found in Crocoblock JetEngine Plugin up to 3.8.6.1 on WordPress and classified as critical. This issue affects the function prepare_where_clause of the component AJAX Action Handler. Such manipulation of the argument filtered_query leads to sql injection.
This vulnerability is traded as CVE-2026-4662. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.