Impact
Crocoblock JetTricks jet‑tricks contains a stored cross‑site scripting flaw that allows attackers to inject malicious scripts into sites that use the plugin. The vulnerability originates from improper neutralization of user input before rendering it on web pages, enabling an attacker to execute arbitrary scripts in the context of site visitors.
Affected Systems
WordPress sites that have the JetTricks plugin installed with any version from the initial release through 1.5.4.1 are affected. The plugin was distributed by Crocoblock as JetTricks and is available as a standard WordPress plugin. No specific WordPress core version is cited, so any WordPress installation that hosts the vulnerable plugin may be impacted.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity with potential for significant impact if exploited. The EPSS score of less than 1% implies low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector likely involves administrative or content‑authoring privileges. If an attacker can inject malicious code into the plugin’s output, all visitors to the affected site would be exposed to the risk.
OpenCVE Enrichment
EUVD