Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows DOM-Based XSS.This issue affects JetBlog: from n/a through <= 2.4.3.
Published: 2025-04-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Crocoblock JetBlog contains a DOM‑Based XSS flaw that allows an attacker to inject arbitrary JavaScript when a victim loads a page containing the vulnerable plugin. The flaw arises from improper neutralization of input during web‑page generation, enabling client‑side script execution in the victim’s browser. This can result in session hijacking, credential theft, or defacement of the site’s content as the script runs with the victim’s privileges. The vulnerability is client‑side and does not provide remote code execution on the server, but it can compromise the confidentiality and integrity of user data and the integrity of the web application’s UI.

Affected Systems

WordPress sites running Crocoblock JetBlog plugin version 2.4.3 or earlier are affected. No other vendors or versions are listed; the advisory specifies all releases through 2.4.3 are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score is less than 1 %, implying a very low probability of exploitation at the time of reporting. It is not listed in the CISA KEV catalog. The flaw is a client‑side web‑application vulnerability; an attacker needs only to entice a user to visit a crafted URL or include a malicious payload on the page, so no special authentication or privileged access is required. The likely attack vector is via the front end, where the untrusted data is reflected into the DOM without proper encoding.

Generated by OpenCVE AI on May 1, 2026 at 10:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBlog to the latest version that removes the XSS flaw
  • If an update is not immediately possible, disable or remove the JetBlog plugin from the WordPress installation
  • Deploy a web‑application firewall rule to block or sanitize suspicious script payloads that target known vulnerable URLs

Generated by OpenCVE AI on May 1, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10955 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetBlog allows DOM-Based XSS. This issue affects JetBlog: from n/a through 2.4.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetBlog allows DOM-Based XSS. This issue affects JetBlog: from n/a through 2.4.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows DOM-Based XSS.This issue affects JetBlog: from n/a through <= 2.4.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 12:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetBlog allows DOM-Based XSS. This issue affects JetBlog: from n/a through 2.4.3.
Title WordPress JetBlog plugin <= 2.4.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:39.899Z

Reserved: 2025-02-14T06:53:10.325Z

Link: CVE-2025-26744

cve-icon Vulnrichment

Updated: 2025-04-15T13:20:33.640Z

cve-icon NVD

Status : Deferred

Published: 2025-04-15T12:15:19.587

Modified: 2026-04-23T15:25:54.203

Link: CVE-2025-26744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:30:15Z

Weaknesses