Impact
The JetSmartFilters plugin contains a DOM‑based Cross‑Site Scripting (XSS) flaw that allows an attacker to inject arbitrary client‑side scripts into the rendered web page. An attacker who can influence the content of a page that loads the plugin could place malicious JavaScript that runs in the victim's browser session, potentially enabling session hijacking, cookie theft, defacement or the execution of arbitrary JavaScript. Because the vulnerability is client‑side, confidentiality and integrity of the server are not directly compromised, but the attacker can control the victim’s browser state.
Affected Systems
The flaw affects Crocoblock’s JetSmartFilters WordPress plugin in all releases up to and including version 3.6.3. WordPress sites that have the plugin installed and are running a version <=3.6.3 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity that requires user interaction. The EPSS score of less than 1 % indicates that exploitation is unlikely at the moment, and the vulnerability has not yet appeared in CISA’s KEV catalog. The attack vector is DOM‑based and depends on a user viewing an affected page; an attacker could embed a crafted URL or manipulate data that the plugin processes to execute injected code in the victim’s browser. While the vulnerability does not expose server‑side secrets, it can lead to client‑side compromise and associated damage.
OpenCVE Enrichment
EUVD