Impact
The vulnerability described as ‘Insertion of Sensitive Information Into Sent Data’ allows an attacker to retrieve sensitive data that JetTabs embeds in outgoing content. An unauthorized user could acquire confidential information, compromising the confidentiality of the site. The weakness is identified as CWE‑201.
Affected Systems
The affected product is Crocoblock JetTabs for WordPress, versions from the earliest release through version 2.2.9 inclusive. Any WordPress site that has the JetTabs plugin installed at one of these versions is potentially susceptible.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact, and the EPSS score of less than 1% implies a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Because JetTabs is a WordPress plugin, an attacker could likely trigger the exposure by sending a crafted HTTP request or interacting with a page that renders the plugin’s output, though the exact attack vector is not specified in the advisory.
OpenCVE Enrichment
EUVD