CVE-2026-32355 HIGH

CVE-2026-32355: WordPress JetEngine plugin < 3.8.4.1 - Deserialization of untrusted data vulnerability

Vendor Crocoblock
Product JetEngine
Weakness CWE-502 · Unsafe deserialization
Published March 13, 2026
Last update April 29, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

Explanation of Vulnerability in Simple Terms

02Summary

JetEngine versions up to 3.8.4.1 contain a deserialization vulnerability that allows authenticated users to execute arbitrary PHP code on the site. An attacker with low-level access can craft malicious serialized data to trigger code execution. This affects all installations running the vulnerable version range.

What an attacker can do

03Attacker Capabilities

Run arbitrary PHP code on the site with the privileges of the web server.

Potential impact on your site

04Site Impact

A compromised low-privilege account can lead to full site takeover, data theft, or malware installation.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account (subscriber or above) on the site.

Key dates

06Disclosure timeline

March 13, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE