Impact
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTricks allows retrieval of embedded sensitive data. This flaw is classified as CWE‑201, resulting in the exposure of confidential information that may be part of the plugin’s configuration or stored data. The vulnerability can compromise the confidentiality of data that should remain private to site administrators or trusted users, potentially leading to broader account compromise or data leakage.
Affected Systems
Crocoblock JetTricks plugin for WordPress, affecting all releases from the initial launch up to and including version 1.5.4.1. Sites running any of these versions are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk. The EPSS score of less than 1% demonstrates a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector, based on the nature of a WordPress plugin, is remote or local depending on user privileges. This inference comes from the plugin context. The description indicates that the flaw permits reading of hidden or embedded data, suggesting that privileged or even unauthenticated users could exploit the plugin if it is exposed to the public; that claim is inferred, not directly stated.
OpenCVE Enrichment
EUVD