Impact
The JetSearch plugin implementation allows an attacker to retrieve embedded sensitive system information without authorization, constituting a clear breach of confidentiality. The weakness is classified as CWE-497, a sensitive information exposure flaw that permits unintended disclosure of data. No denial of service or code execution capability is present; the primary consequence is the compromise of protected data that a legitimate user should not access.
Affected Systems
The affected product is Crocoblock’s JetSearch for WordPress. All releases through version 3.6.1.2 are vulnerable; the issue does not impact later releases. The problem is present in any installation of the plugin where the default settings expose internal information via the web interface.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score of less than 1% suggests that, so far, exploitation attempts are scarce, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability exists through version 3.6.1.2. Based on the description, the likely attack vector is a remote HTTP request to the JetSearch endpoint, where the exposed data can be retrieved by any user able to access the plugin’s search interface without authentication.
OpenCVE Enrichment