WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.2%
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
In short
The JetBlog plugin for WordPress versions 2.4.8 and earlier allows anyone to access sensitive information without needing to log in, exposing data that should be private.
Technical detail
An unauthenticated attacker can exploit insufficient access controls in JetBlog <= 2.4.8 to retrieve sensitive data through direct requests, potentially exposing private content or configuration details without requiring user authentication.
Summary generated and translated by AI from the official description.
Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Jetimpex Inc. · JetBlog