Junglewise Threat Intelligence

CVE-2026-54836: YMC Filter SQL injection in Filter & Grids plugin

CVE-2026-54836 · Severity: critical · CVSS 9.3 · Published 2026-06-25

Executive brief

The Filter & Grids (YMC Filter) plugin for WordPress is vulnerable to a critical security flaw that allows attackers to interfere with the website's database. This plugin is used to create searchable filters and grids for website content. An exploit could allow an unauthorized person to steal sensitive information from the database or disrupt site operations.

Technical details

A SQL injection vulnerability exists in the YMC Filter (also known as Filter & Grids) plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL queries against the backend database. This is achieved by sending specially crafted requests to the affected component. Successful exploitation could lead to unauthorized data exfiltration or limited impact on database availability. The issue is resolved in version 3.11.6.

Affected products

  • YMC Filter & Grids (YMC Filter) up to 3.11.5

Timeline

  • 2026-06-07: disclosed: Reported by Nguyen Ba Khanh
  • 2026-06-18: advisory: Patchstack published advisory
  • 2026-06-25: patched: Version 3.11.6 released to address the vulnerability

References