Impact
The JetBlog plugin for WordPress contains a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. An attacker who can inject content that is saved and later displayed will cause arbitrary JavaScript to execute in the browsers of any user who views the affected page. This can lead to session theft, defacement, or further exploitation of the host system.
Affected Systems
Crocoblock JetBlog plugin versions up through 2.4.4.1 on WordPress sites. All installations of JetBlog that have not been updated beyond that version are vulnerable. The vulnerability is present in every release from the earliest available version up to and including 2.4.4.1.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating a moderate impact. The EPSS score is less than 1 %, suggesting that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that successful exploitation requires an attacker to supply malicious input that will be stored in the plugin’s content fields and later rendered for other users; this requires access to the administrative or content creation interface or some other means of submitting a payload.
OpenCVE Enrichment