CVE-2025-49931: WordPress JetSearch plugin <= 3.5.10 - SQL Injection vulnerability
Published Oct 22, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSearch jet-search allows Blind SQL Injection.This issue affects JetSearch: from n/a through <= 3.5.10.
Affected Software
1 affected component
Crocoblock JetSearch<=3.5.10
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49931?
CVE-2025-49931 is rated as critical due to its ability to allow Blind SQL Injection.
2
How do I fix CVE-2025-49931?
To fix CVE-2025-49931, update the CrocoBlock JetSearch plugin to a version higher than 3.5.10.
3
Which versions of JetSearch are affected by CVE-2025-49931?
CVE-2025-49931 impacts all versions of JetSearch from n/a up to and including 3.5.10.
4
What is the nature of the vulnerability in CVE-2025-49931?
The vulnerability in CVE-2025-49931 involves improper neutralization of special elements in SQL commands, leading to SQL Injection.
5
Who is affected by CVE-2025-49931?
Users of CrocoBlock JetSearch and WordPress JetSearch versions 3.5.10 and below are affected by CVE-2025-49931.