Impact
JetSmartFilters versions up to 3.8.3 contain an unauthenticated SQL Injection flaw that allows an attacker to inject arbitrary SQL commands. The weakness, classified as CWE-89, could enable the attacker to read, modify, or delete database data. The vulnerability is exploitable without user credentials, making it a critical risk for any publicly accessible WordPress site using the plugin.
Affected Systems
The affected product is the JetSmartFilters plugin for WordPress, distributed by Crocoblock and Jetimpex Inc. All installations running version 3.8.3 or earlier are at risk. There is no discernible requirement for authentication or special user roles; any actor who can reach the plugin’s endpoints can potentially exploit the flaw.
Risk and Exploitability
The CVSS score of 9.3 indicates a very high severity and broad impact, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because exploitation does not require credentials, an attacker can simply craft a malicious request to any accessible endpoint that passes through the plugin’s input handling. Successful exploitation would give full control over the database, effectively compromising the entire website’s integrity and confidentiality.
OpenCVE Enrichment