Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-61975 exposes sensitive system information, allowing an unauthorized user to retrieve embedded sensitive data from the Crocoblock JetReviews WordPress plugin. This vulnerability is an instance of CWE-497 (Sensitive Data Exposure). The flaw can compromise confidentiality of the site and its data. No denial‑of‑service or code‑execution capabilities are described. The CVSS base score of 5.3 indicates moderate impact.

Affected Systems

The vulnerability affects the JetReviews plugin for WordPress released by Crocoblock, all versions from the earliest available up to and including 3.0.1.

Risk and Exploitability

With an EPSS score of less than 1% the likelihood of exploitation appears low and the issue is not listed in the CISA KEV catalog. The likely attack vector is inferred to be a remote unauthenticated or low‑privilege user able to invoke the plugin’s data retrieval functions; the description does not mention required authentication, so the attack may be feasible through publicly exposed endpoints. The moderate CVSS score and low exploitation probability suggest that while the vulnerability is not immediately critical, it should be addressed promptly to avoid potential data compromise.

Generated by OpenCVE AI on August 1, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the JetReviews plugin to a version newer than 3.0.1 as soon as one becomes available.
  • Review and delete any configuration files that are unintentionally exposed by the plugin, ensuring that only authorized users can access sensitive data.
  • Apply standard web‑application access controls, such as restricting plugin data retrieval endpoints to authenticated administrators, to mitigate the risk of unauthorized data exposure.

Generated by OpenCVE AI on August 1, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
Title WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:13:44.946Z

Reserved: 2026-07-13T06:13:55.444Z

Link: CVE-2026-61975

cve-icon Vulnrichment

Updated: 2026-07-13T13:13:41.229Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere