Impact
CVE-2026-61975 exposes sensitive system information, allowing an unauthorized user to retrieve embedded sensitive data from the Crocoblock JetReviews WordPress plugin. This vulnerability is an instance of CWE-497 (Sensitive Data Exposure). The flaw can compromise confidentiality of the site and its data. No denial‑of‑service or code‑execution capabilities are described. The CVSS base score of 5.3 indicates moderate impact.
Affected Systems
The vulnerability affects the JetReviews plugin for WordPress released by Crocoblock, all versions from the earliest available up to and including 3.0.1.
Risk and Exploitability
With an EPSS score of less than 1% the likelihood of exploitation appears low and the issue is not listed in the CISA KEV catalog. The likely attack vector is inferred to be a remote unauthenticated or low‑privilege user able to invoke the plugin’s data retrieval functions; the description does not mention required authentication, so the attack may be feasible through publicly exposed endpoints. The moderate CVSS score and low exploitation probability suggest that while the vulnerability is not immediately critical, it should be addressed promptly to avoid potential data compromise.
OpenCVE Enrichment