CVE-2026-3496 | Crocoblock JetBooking Plugin up to 4.0.3 on WordPress check_in_date sql injection
A vulnerability was found in Crocoblock JetBooking Plugin up to 4.0.3 on WordPress. It has been declared as critical. This issue affects some unknown processing. Executing a manipulation of the argument check_in_date can lead to sql injection.
This vulnerability appears as CVE-2026-3496. The attack may be performed from remote. There is no available exploit.