Impact
This vulnerability in Crocoblock JetBlocks For Elementor allows an attacker to retrieve embedded sensitive data that should remain protected. The weakness is classified as CWE-497, which concerns private class methods being publicly exposed, potentially leaking internal information. Consequently, an unauthorized user could obtain confidential system information, compromising data confidentiality and potentially aiding further attacks.
Affected Systems
The affected product is Crocoblock JetBlocks For Elementor, versions up to and including 1.5.0. No specific production environment details are available beyond the vendor and plugin name.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the use of the plugin on a WordPress site; for example, a malicious actor could craft a block or content payload that triggers the exposure of sensitive data to the attacker’s control sphere. No active exploitation has been reported, but the data leakage could still be leveraged for reconnaissance or further compromise.
OpenCVE Enrichment