Impact
Improper neutralization of user input during web page generation allows a DOM-based XSS attack, enabling attackers to inject and execute arbitrary JavaScript within a victim’s browser. This flaw is categorised as CWE-79 and can lead to malicious content execution, defacement, data theft, or session hijacking through the affected JetSearch plugin.
Affected Systems
The vulnerability impacts the Crocoblock JetSearch plugin for WordPress, affecting all releases up to and including version 3.5.7. Any site installing these versions is therefore exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, attackers likely exploit the flaw via crafted query strings or content embedded by the plugin, delivering harmful JavaScript to visitors who view affected pages.
OpenCVE Enrichment
EUVD