Impact
The JetProductGallery plugin for WordPress has a weakness in how it handles user input during page rendering. The flaw is a DOM‑based cross‑site scripting (CWE‑79) that enables an attacker to inject malicious script into a page. When a visitor opens a page containing the crafted input, the browser executes the attacker’s JavaScript, giving the attacker code execution within the context of the website.
Affected Systems
Crocoblock’s JetProductGallery WordPress plugin, all releases up to and including version 2.1.22, is affected. No other vendors or product variants are listed, and no specific configuration details were provided.
Risk and Exploitability
The CVSS score of 6.5 describes moderate severity. An EPSS score of <1% indicates that the vulnerability is unlikely to be widely exploited at the present time. It is not included in CISA’s KEV catalog, so no active exploitation has been reported. Exploitation requires an attacker to supply crafted payload content, typically via a link or embedded element, which the victim’s browser then processes.
OpenCVE Enrichment
EUVD