Description
Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows Retrieve Embedded Sensitive Data.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.
Published: 2026-02-20
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the insertion of sensitive information into data that is sent to the client, allowing an attacker to retrieve embedded sensitive data. This flaw, classified as CWE‑201 (Information Exposure Through an Improperly Guarded Resource), can lead to the disclosure of confidential information that the plugin handles. The CVE description indicates that the issue exists in all versions from the first release up to and including 1.2.8, so any site running one of those versions is susceptible. If exploited, the exposed data could compromise user privacy and trust, but no privilege escalation or code execution is described.

Affected Systems

The affected product is the JobBoard Job listing plugin developed by Themeglow, versions up to 1.2.8. WordPress sites that have installed this plugin within that version range are impacted. The vulnerability exists in the plugin's product code, not in WordPress core.

Risk and Exploitability

The CVSS score of 5.9 reflects a moderate severity, and the EPSS score of <1% indicates that the likelihood of exploitation is currently low. The vulnerability is not included in the CISA KEV catalog, further suggesting a lower threat level. The attack vector is not explicitly stated, but because the flaw involves data sent to the client, the likely vector is a web-based request to the plugin's output. Remote attackers could potentially trigger the flaw by accessing public pages that include the plugin, or they could manipulate query parameters to prompt the plugin to reveal sensitive data. No authentication requirement is mentioned, so the exposure could be publicly available.

Generated by OpenCVE AI on April 29, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of the JobBoard Job listing plugin (≥1.2.9)
  • Disable or remove the plugin if it is not required for site functionality
  • Review plugin settings and restrict any endpoints that expose sensitive information

Generated by OpenCVE AI on April 29, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeglow
Themeglow jobboard Job Listing
Wordpress
Wordpress wordpress
Vendors & Products Themeglow
Themeglow jobboard Job Listing
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows Retrieve Embedded Sensitive Data.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.
Title WordPress JobBoard Job listing plugin <= 1.2.8 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Themeglow Jobboard Job Listing
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:56.564Z

Reserved: 2025-12-24T14:00:18.228Z

Link: CVE-2025-68855

cve-icon Vulnrichment

Updated: 2026-02-25T16:52:45.511Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:14.433

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-68855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:45:13Z

Weaknesses