Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JetSearch plugin implementation allows an attacker to retrieve embedded sensitive system information without authorization, constituting a clear breach of confidentiality. The weakness is classified as CWE-497, a sensitive information exposure flaw that permits unintended disclosure of data. No denial of service or code execution capability is present; the primary consequence is the compromise of protected data that a legitimate user should not access.

Affected Systems

The affected product is Crocoblock’s JetSearch for WordPress. All releases through version 3.6.1.2 are vulnerable; the issue does not impact later releases. The problem is present in any installation of the plugin where the default settings expose internal information via the web interface.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. The EPSS score of less than 1% suggests that, so far, exploitation attempts are scarce, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability exists through version 3.6.1.2. Based on the description, the likely attack vector is a remote HTTP request to the JetSearch endpoint, where the exposed data can be retrieved by any user able to access the plugin’s search interface without authentication.

Generated by OpenCVE AI on August 1, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JetSearch to a version newer than 3.6.1.2 as provided by Crocoblock
  • Configure WordPress and the JetSearch plugin to restrict the search API to authenticated users or IP ranges that require the sensitive data
  • Verify that no custom code or additional plugins expose the JetSearch endpoints; if custom-sensitive information is returned.

Generated by OpenCVE AI on August 1, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock
Crocoblock jetsearch
Wordpress
Wordpress wordpress
Vendors & Products Crocoblock
Crocoblock jetsearch
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
Title WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Crocoblock Jetsearch
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:30:13.175Z

Reserved: 2026-07-13T06:13:55.444Z

Link: CVE-2026-61977

cve-icon Vulnrichment

Updated: 2026-07-13T14:30:07.909Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere