Impact
Crocoblock JetWooBuilder Plugin for WordPress contains an insertion of sensitive information into sent data vulnerability that allows attackers to retrieve embedded sensitive data from the plugin’s output. The weakness is classified as a CWE-201 data exposure flaw and can compromise the confidentiality of information that the plugin is designed to process and display.
Affected Systems
WordPress sites that use the JetWooBuilder extension by Crocoblock. Any installation running version 2.1.20 or earlier is vulnerable; newer releases are not known to be affected.
Risk and Exploitability
The vulnerability is scored with a CVSS score of 6.5, placing it in the moderate severity range. The EPSS score of less than 1% indicates a very low probability of exploitation at this time, and it is not included in the CISA KEV catalog. The likely attack vector is access to the plugin’s output—whether authenticated or unauthenticated—where the attacker can trigger the data exposition by requesting affected endpoints. Successful exploitation would expose confidential data processed by the plugin but would require the ability to invoke the vulnerable functionality.
OpenCVE Enrichment
EUVD