Junglewise Threat Intelligence

CVE-2026-61977: Crocoblock JetSearch sensitive information disclosure in jet-search

CVE-2026-61977 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Technologies: Crocoblock JetSearch. Vendors: Crocoblock.

Executive brief

Crocoblock JetSearch is a WordPress plugin used to create advanced search functionality for websites. A security vulnerability in this plugin allows unauthorized individuals to access sensitive system information that should be protected. This could lead to the exposure of internal site data, potentially aiding attackers in further compromising the website or its users.

Technical details

A vulnerability classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere) exists in the Crocoblock JetSearch plugin for WordPress. The flaw allows an unauthenticated remote attacker to retrieve embedded sensitive system data due to improper access controls within the 'jet-search' component. The issue affects all versions up to and including 3.6.1.2. A fix is available in version 3.6.1.3. The attack can be carried out over the network without user interaction.

Affected products

  • Crocoblock JetSearch <= 3.6.1.2

Timeline

  • 2026-07-13: advisory: Advisory published by Patchstack and NVD
  • 3.6.1.3: patched: Vulnerability addressed in version 3.6.1.3

References

Related threats