Impact
An improper neutralization of input during web page generation vulnerability (CWE-79) allows attackers to store malicious scripts in the JetProductGallery plugin, which are then executed whenever a page containing the gallery is loaded. This stored cross‑site scripting can lead to session hijacking, defacement, credential theft, or the execution of arbitrary commands in the context of the site’s logged‑in users, potentially compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The vulnerability affects Crocoblock’s JetProductGallery plugin for WordPress, versions from the earliest release through and including 2.2.0.2. Any WordPress installation that has one of these legacy versions installed is potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to require access to the site’s administrative interface or the ability to insert content into the gallery, allowing an attacker to inject and store malicious code that is then served to all visitors.
OpenCVE Enrichment
EUVD