Junglewise Threat Intelligence

CVE-2026-61975: Crocoblock JetReviews sensitive data exposure

CVE-2026-61975 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Vendors: Crocoblock.

Executive brief

Crocoblock JetReviews is a WordPress plugin used by website professionals to add review and rating functionality to their sites. A security vulnerability in versions 3.0.1 and earlier allows unauthorized individuals to access sensitive system information that should be protected. This could lead to the exposure of internal configuration details, potentially aiding further attacks against the website.

Technical details

A sensitive data exposure vulnerability (CWE-497) exists in the Crocoblock JetReviews plugin (jet-reviews) for WordPress. The flaw allows an unauthenticated remote attacker to retrieve embedded sensitive system information from the "unauthorized control sphere." This typically occurs when internal system details or configuration data are improperly exposed through public-facing interfaces or API responses. The issue affects all versions up to and including 3.0.1. A fix is available in version 3.1.0.

Affected products

  • Crocoblock JetReviews <= 3.0.1

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory
  • 2026-07-13: patched: Fixed in version 3.1.0

References

Related threats