Executive brief
JetSearch is a popular WordPress plugin used to provide advanced AJAX-based search functionality for websites. A critical security flaw allows unauthenticated attackers to perform SQL injection attacks, which could lead to the theft of sensitive information from the website's database. This vulnerability is particularly dangerous as it can be exploited remotely without any user interaction or login credentials.
Technical details
A SQL injection vulnerability exists in the JetSearch plugin for WordPress in versions up to and including 3.5.17. The flaw is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and can be exploited by an unauthenticated attacker over the network. By sending specially crafted requests, an attacker can bypass security controls to execute arbitrary SQL queries against the backend database. This could result in the unauthorized retrieval of sensitive data (Confidentiality: High) and potential service disruption (Availability: Low). The issue is resolved in version 3.5.17.1.
Affected products
- Jetimpex Inc. (Crocoblock) JetSearch <= 3.5.17
Timeline
- 2026-04-21: other: Vulnerability reported by researcher Bonds
- 2026-06-05: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date
- 2026-06-17: patched: Patch confirmed available in version 3.5.17.1