Junglewise Threat Intelligence

CVE-2026-61976: Crocoblock JetBlocks For Elementor sensitive information exposure

CVE-2026-61976 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Vendors: Crocoblock.

Executive brief

Crocoblock JetBlocks is a WordPress plugin used to add specialized headers, footers, and interactive elements to websites built with the Elementor page builder. A security flaw in versions 1.5.0 and earlier allows unauthorized individuals to access sensitive system information that should be restricted. This could potentially expose configuration details or other internal data, providing attackers with information needed to plan further strikes against the website.

Technical details

An Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) vulnerability exists in the Crocoblock JetBlocks For Elementor plugin (jet-blocks). The flaw allows an unauthenticated remote attacker to retrieve embedded sensitive data from the system. The vulnerability is present in versions up to and including 1.5.0. The issue was addressed in version 1.5.0.1. The attack vector is network-based with low complexity and requires no user interaction or elevated privileges.

Affected products

  • Crocoblock JetBlocks For Elementor <= 1.5.0

Timeline

  • 2026-07-13: advisory: NVD publication date
  • 1.5.0.1: patched: First version identified as unaffected

References

Related threats