CVE-2025-54008: WordPress JetSmartFilters <= 3.6.7 - Sensitive Data Exposure Vulnerability
Published Aug 20, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows Retrieve Embedded Sensitive Data.This issue affects JetSmartFilters: from n/a through <= 3.6.7.
Affected Software
1 affected component
Crocoblock JetSmartFilters<=3.6.7
Remediation
Information
Update the WordPress JetSmartFilters plugin to the latest available version (at least 3.6.7.1).
Event History
Aug 20, 2025
CVE Published
via MITRE·08:03 AM
Data Sourced
via MITRE·08:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54008?
The severity of CVE-2025-54008 is considered moderate as it allows for the retrieval of sensitive data due to improper handling.
2
How do I fix CVE-2025-54008?
To fix CVE-2025-54008, upgrade JetSmartFilters to version 3.6.8 or later.
3
What versions of JetSmartFilters are affected by CVE-2025-54008?
CVE-2025-54008 affects JetSmartFilters versions up to 3.6.7.
4
What type of vulnerability is CVE-2025-54008?
CVE-2025-54008 is an insertion of sensitive information into sent data vulnerability.
5
Who is impacted by CVE-2025-54008?
Users of Crocoblock and WordPress JetSmartFilters versions up to 3.6.7 are impacted by CVE-2025-54008.