Junglewise Threat Intelligence

CVE-2026-56067: Crocoblock JetSmartFilters unauthenticated SQL injection

CVE-2026-56067 · Severity: critical · CVSS 9.3 · Published 2026-06-26

Vendors: Crocoblock.

Executive brief

JetSmartFilters is a WordPress plugin used to create advanced filtering systems for e-commerce and content-heavy websites. A critical security flaw allows unauthorized individuals to interact directly with the website's database without needing a login. This could lead to the theft of sensitive customer data, exposure of administrative credentials, or disruption of site operations.

Technical details

A SQL injection vulnerability exists in the JetSmartFilters plugin for WordPress (versions 3.8.3 and below) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers, meaning no user account or special privileges are required to trigger the exploit. By sending specially crafted network requests, an attacker can bypass intended query logic to read sensitive data from the database or potentially impact site availability. The issue is resolved in version 3.8.3.1.

Affected products

  • Crocoblock (Jetimpex Inc.) JetSmartFilters <= 3.8.3

Timeline

  • 2026-06-17: other: Reported by Nguyen Ba Khanh
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date
  • 2026-06-26: patched: Version 3.8.3.1 released to address the vulnerability

References

Related threats