Executive brief
JetSmartFilters is a popular WordPress plugin used to create advanced filtering systems for e-commerce and content-heavy websites. A critical security flaw allows unauthenticated attackers to perform SQL injection, which could lead to the theft of sensitive customer data or unauthorized access to the site's database. This vulnerability is particularly dangerous as it can be exploited remotely without any login credentials.
Technical details
An unauthenticated SQL injection vulnerability exists in the JetSmartFilters plugin for WordPress (versions 3.8.1 and below). The flaw is classified as CWE-89, indicating improper neutralization of special elements used in an SQL command. An attacker can exploit this by sending specially crafted network requests to the affected site, allowing them to bypass security controls and directly query the underlying database. This can result in the extraction of sensitive information, such as user credentials or site configuration data. The vulnerability is remediated in version 3.8.1.1.
Affected products
- Jetimpex Inc. (Crocoblock) JetSmartFilters <= 3.8.1
Timeline
- 2026-05-17: other: Reported by Austin Ginder
- 2026-06-02: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD