Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected XSS. A malicious URL or input that reaches the JetBlog plugin can contain executable script, which will run in the context of the site when viewed by an unsuspecting user. The attacker could then hijack user sessions, steal cookies, or inject additional malicious content. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
WordPress sites that install the Crocoblock JetBlog plugin version 2.4.4 or earlier are affected. All such installations that expose user‑controlled inputs to JetBlog’s rendering routines are at risk.
Risk and Exploitability
The CVSS score of 6.5 assigns medium severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require the attacker to supply crafted input and rely on a victim to interact with the malicious link or page, so it is a user‑interaction dependent attack. Given the modest severity and low exploitation probability, the immediate threat level is moderate, but prompt remediation is recommended to prevent future abuse as the threat landscape evolves.
OpenCVE Enrichment