Executive brief
JetBlog is a WordPress plugin used to create and display dynamic blog content and news feeds. A security flaw in versions 2.4.8 and earlier allows unauthorized individuals to access sensitive system information that should be private. This exposure could provide attackers with technical details needed to launch more advanced attacks against the website, potentially compromising its security or user data.
Technical details
A Sensitive Data Exposure vulnerability exists in the JetBlog plugin (versions <= 2.4.8) for WordPress due to the failure to clear debug information or properly restrict access to sensitive system data (CWE-1258). An unauthenticated remote attacker can exploit this by accessing specific endpoints or files that leak technical details about the environment. This information disclosure can be leveraged to facilitate further attacks against the host. The vulnerability is rated with a CVSS 3.1 base score of 7.5 (High) due to the lack of required authentication and high confidentiality impact. A fix is available in version 2.4.8.1.
Affected products
- Jetimpex Inc. (Crocoblock) JetBlog <= 2.4.8
Timeline
- 2026-05-17: other: Reported by Austin Ginder
- 2026-06-10: disclosed: Vulnerability published by Patchstack
- 2026-06-17: advisory: NVD published date