Impact
An improper neutralization of input during web page generation allows an attacker to store malicious JavaScript in the plugin’s content, which is executed when site visitors view affected pages. The flaw is classified as CWE‑79 and results in a stored cross‑site scripting vulnerability.
Affected Systems
The JetBlocks For Elementor plugin distributed by Crocoblock is affected in all releases up to and including version 1.3.16. Any WordPress installation running a vulnerable version of this plugin is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through users with privilege to create or edit content in the JetBlocks editor; success would result in the injected script executing in the browsers of site visitors. Beyond the injection itself, no additional impact is specified.
OpenCVE Enrichment
EUVD