Sceawere

Vulnerability Detail

CVE-2026-96328UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Blind SQL Injection in JNews-Pay-Writer

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
jegtheme
Product
JNews - Pay Writer
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows Blind SQL Injection.This issue affects JNews - Pay Writer: from n/a through 12.0.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-10-09T10:16:43.600Z",
  "pubdate": "2026-10-09T10:16:43.600Z",
  "executiveSummary": "The JNews - Pay Writer plugin for WordPress is susceptible to a Blind SQL Injection vulnerability, categorized under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).\nThis vulnerability allows an unauthenticated or authenticated attacker to inject arbitrary SQL queries into the database through the affected component, potentially leading to unauthorized data exfiltration or manipulation.\nThe scope of impact includes the compromise of sensitive data stored within the WordPress database, which may contain user credentials, payment details, or proprietary content.\nThe flaw affects JNews - Pay Writer versions from n/a through 12.0.1.\nThe risk is critical as it provides a pathway for attackers to bypass application-layer security controls and perform database-level operations without direct system access.\nSuccessful exploitation requires the application to interact with user-supplied input without adequate sanitization or parameterized queries, enabling attackers to infer database contents by observing time-based or boolean-based response discrepancies.",
  "technicalDetails": "The vulnerability resides in the JNews - Pay Writer component of the jegtheme JNews ecosystem. The core issue is the failure to properly neutralize malicious input before incorporating it into dynamic SQL statements. This lack of input sanitization and failure to implement parameterized queries (prepared statements) allows an attacker to manipulate the structure of database queries.\nIn a Blind SQL Injection scenario, the application does not typically return direct database errors or data to the user. Instead, the attacker leverages boolean inference or time-based payloads to extract data. By injecting conditional SQL statements, the attacker observes differences in the HTTP response content (boolean-based) or response latency (time-based) to confirm the truthfulness of the injected queries.\nStep-by-step attack flow: 1. Identification: The attacker probes input vectors within the JNews - Pay Writer plugin to identify parameters that reflect changes in the backend database execution. 2. Injection: The attacker crafts a payload containing SQL operators (e.g., 'AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)--') designed to force the database to pause or return a specific state. 3. Evaluation: The attacker monitors the application's response time or content. A consistent delay or specific HTTP code confirms the presence of the injection point.\nBecause the input is processed directly into the database query engine, an attacker can enumerate database schemas, table structures, and sensitive row data. If the database user account used by the WordPress installation has excessive privileges, this could theoretically be escalated to modifying administrative accounts or altering site settings. The vulnerable component fails to enforce strict type checking or escaping of user-provided data, essentially acting as a conduit for arbitrary SQL execution.\nThe exposure is network-based, meaning any remote actor with access to the web server can attempt exploitation. Given the version range from n/a through 12.0.1, all legacy and current installations within this bracket are considered vulnerable to query manipulation. Post-exploitation impact varies depending on database configuration, but typically results in complete confidentiality loss of stored data."
}
CVE-2026-96328: Blind SQL Injection in JNews-Pay-Writer (CRITICAL Severity, CVSS: 9.3) | Sceawere