Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject and persist malicious scripts within the JetSmartFilters plugin’s output. When an affected user or page is rendered, the stored script runs in the victim’s browser, potentially enabling session hijacking, credential theft, or execution of arbitrary client‑side code. The weakness is described by CWE‑79.
Affected Systems
Crocoblock JetSmartFilters plugins with versions up to and including 3.6.8 are impacted. The issue originates from an improper sanitization of user input that is later displayed in generated web pages. All WordPress sites that have installed or enabled these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in CISA KEV. Attackers likely need to supply crafted input through the plugin’s interface or an exposed API endpoint; the stored nature of the XSS allows the malicious payload to be executed whenever an impacted page is viewed by any user.
OpenCVE Enrichment
EUVD