Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Crocoblock JetBlocks For Elementor allows an attacker to retrieve embedded sensitive data that should remain protected. The weakness is classified as CWE-497, which concerns private class methods being publicly exposed, potentially leaking internal information. Consequently, an unauthorized user could obtain confidential system information, compromising data confidentiality and potentially aiding further attacks.

Affected Systems

The affected product is Crocoblock JetBlocks For Elementor, versions up to and including 1.5.0. No specific production environment details are available beyond the vendor and plugin name.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the use of the plugin on a WordPress site; for example, a malicious actor could craft a block or content payload that triggers the exposure of sensitive data to the attacker’s control sphere. No active exploitation has been reported, but the data leakage could still be leveraged for reconnaissance or further compromise.

Generated by OpenCVE AI on August 1, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JetBlocks To A Version Greater Than 1.5.0
  • If an update is unavailable, disable the JetBlocks For Elementor plugin until a fix is released
  • Remove or sanitize any content blocks that may contain sensitive data before publishing

Generated by OpenCVE AI on August 1, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.
Title WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:46:29.399Z

Reserved: 2026-07-13T06:13:55.444Z

Link: CVE-2026-61976

cve-icon Vulnrichment

Updated: 2026-07-13T13:46:25.948Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere