Impact
The vulnerability allows an attacker to cause restricted or administrator‑only content to be indexed by Joomla’s Smart Search feature using the identity of the indexing administrator. Consequently, content that should be hidden from public visitors is stored in the public search index and becomes viewable by any site visitor. This leads to accidental disclosure of confidential or privileged information without the need for authentication. The flaw is a CWE‑524 information disclosure vulnerability.
Affected Systems
Affected vendors include Regular Labs, which provides several Joomla extensions such as Articles Anywhere, Conditional Content, Modules Anywhere, ReReplacer, Snippets Pro, Sourcerer, and Tabs & Accordions Pro. The specific versions impacted are not listed in the advisory, so any release that patch is applied.
Risk and Exploitability
The EPSS score of 0.00249 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a normal search request made by a publicly accessible visitor, which triggers the indexing process. An attacker does not need privileged credentials to leverage the flaw; they merely need to cause the search index to be updated. The impact is purely informational, exposing content that was intended to remain restricted. Organizations using these Regular Labs extensions should consider the vulnerability a low‑to‑moderate risk until a fix is applied, but should not any breach of content confidentiality can have downstream effects on trust and compliance.
OpenCVE Enrichment