Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup jet-popup allows DOM-Based XSS.This issue affects JetPopup: from n/a through <= 2.0.15.
Published: 2025-07-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation in the Crocoblock JetPopup plugin allows a DOM‑based cross‑site scripting attack. When an attacker can supply custom data that is reflected by the plugin, malicious JavaScript can execute in the victim’s browser. The payload can read or modify page content, steal session cookies, or perform other client‑side attacks that compromise user confidentiality and integrity. The described vulnerability does not grant direct code execution on the server, but it enables attackers to hijack sessions or trick users into phishing interactions.

Affected Systems

WordPress sites that have the Crocoblock JetPopup plugin installed with versions up to and including 2.0.15 are affected. This includes any installation that has not yet upgraded beyond that release. Users of the plugin should verify the exact version of JetPopup they are running.

Risk and Exploitability

The CVSS v3.1 score of 6.5 indicates a medium severity vulnerability. The EPSS score is reported as < 1%, suggesting a low likelihood of exploitation at the time of this analysis. The attack vector is inferred to be user‑initiated: an attacker can craft a URL or form entry that injects script and relies on a victim visiting the affected page. Because the flaw operates in the browser, it can apply to both authenticated and anonymous users, widening the attack surface. The vulnerability is not currently listed in CISA’s KEV catalog, but it remains publicly known and may be leveraged by automated scanners or targeted attackers.

Generated by OpenCVE AI on April 30, 2026 at 09:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the JetPopup plugin to a version newer than 2.0.15 to eliminate the input handling flaw.
  • Apply the latest WordPress core and all other plugin updates to reduce collateral attack vectors.
  • Deploy a web application firewall or content security policy that blocks inline scripts and mitigates script injection.
  • If an upgrade is unavailable, consider disabling the JetPopup plugin or restricting its use on sensitive pages until a fix is applied.

Generated by OpenCVE AI on April 30, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21686 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows DOM-Based XSS. This issue affects JetPopup: from n/a through 2.0.15.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows DOM-Based XSS. This issue affects JetPopup: from n/a through 2.0.15. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup jet-popup allows DOM-Based XSS.This issue affects JetPopup: from n/a through <= 2.0.15.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00031}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows DOM-Based XSS. This issue affects JetPopup: from n/a through 2.0.15.
Title WordPress JetPopup plugin <= 2.0.15 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:03:38.567Z

Reserved: 2025-07-16T08:51:16.734Z

Link: CVE-2025-53994

cve-icon Vulnrichment

Updated: 2025-07-16T19:49:15.953Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:27.267

Modified: 2026-04-23T15:32:40.340

Link: CVE-2025-53994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:45:25Z

Weaknesses