CVE-2026-61977

WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.


We have discovered 17,891 live websites that are affected by CVE-2026-61977.

Run a Free Instant Scan




Affected Software

Product  Crocoblock JetSearch
Category Wordpress Plugins
Vulnerable Domains17,891 live websites (100% of Crocoblock JetSearch install base)
Vulnerable Versions
  • from 0 through 3.6.1.2
Vulnerable Versions Count71 versions ( 100% of all versions)



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • Ananda Dhakal (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2026-61977
United States4,542 websites



Germany1,380 websites
Brazil1,176 websites
France940 websites
Israel752 websites
GB741 websites
Netherlands725 websites
Spain647 websites
Iran436 websites
Italy404 websites

Website Distribution by TLD

Number of websites using CVE-2026-61977
.com6,427 websites
.com.br1,040 websites
.org787 websites
.de722 websites
.nl648 websites
.fr503 websites
.co.uk452 websites
.it290 websites
.es282 websites
.com.au250 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-61977

Top websites that are affected by CVE-2026-61977. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***.com United States*,***
********.com United States**,***
*************.org United States**,***
*****************.org United States**,***
************.com United States**,***
********************.***.uk United States**,***
*************.com United States**,***
********.org United States**,***
******.com United States**,***
See full domain list

FAQ

A total of 17,891 websites have been identified as vulnerable to CVE-2026-61977, based on global website indexing conducted by WebTechSurvey.
The Crocoblock JetSearch is affected by the CVE-2026-61977 vulnerability.
Crocoblock JetSearch versions up to and including 3.6.1.2 are vulnerable to CVE-2026-61977.