Impact
The vulnerability in Crocoblock JetSmartFilters versions up through 3.6.7 allows an attacker to insert sensitive information into transmitted data structures and retrieve embedded sensitive data. This flaw can expose personal or confidential information that the plugin processes or stores, compromising data confidentiality. The weakness is classified as a data exposure flaw (CWE-201).
Affected Systems
WordPress sites using the JetSmartFilters plugin from Crocoblock, specifically all releases up to and including version 3.6.7, are affected. Any WordPress installation deploying this plugin without an update to a later version inherits this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely occur through the plugin’s data handling mechanisms—such as form submissions or AJAX requests—where an attacker can craft requests that embed malicious payloads or reveal sensitive data. No public exploitation reports are currently known, but the flaw permits unauthorized data disclosure if triggered.
OpenCVE Enrichment
EUVD