Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12.
Published: 2025-12-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site Scripting (XSS) vulnerability in Crocoblock JetTabs
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from improper neutralization of user‑supplied input that is rendered in the page by the JetTabs plugin. This allows an attacker to inject arbitrary JavaScript into the browser of anyone who visits a page that contains the affected tab content. The injected script can execute in the victim’s context, enabling defacement, cookie theft, session hijacking, or further malware delivery. The weakness is classified as an XSS flaw (CWE‑79).

Affected Systems

Any WordPress site that has the JetTabs plugin from Crocoblock installed with a version up to and including 2.2.12 is affected. Versions older than the earliest documented release are also included as part of the affected range, but the list of supported earlier releases is not specified. Sites without the plugin or with newer versions are not impacted.

Risk and Exploitability

The CVSS score of 6.5 places the vulnerability in the medium severity band, and the EPSS score of less than 1% indicates a very low probability of exploitation at the time of this analysis. The CVE has not been added to the CISA KEV catalog. The likely attack vector is a DOM‑based XSS that requires an attacker to deliver a malicious link or malicious content within a tab to a victim. Successful exploitation would require the victim’s browser to render the tab content, so the threat is reputational and user‑centric rather than system‑wide

Generated by OpenCVE AI on April 28, 2026 at 10:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Crocoblock JetTabs to version 2.2.13 or later
  • Remove or sanitize any custom tab content that may contain untrusted user input
  • Implement a Content Security Policy or WAF rule to block inline scripts and mitigate XSS until the patch is applied

Generated by OpenCVE AI on April 28, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through 2.2.12. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock
Crocoblock jettabs
Wordpress
Wordpress wordpress
Vendors & Products Crocoblock
Crocoblock jettabs
Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Dec 2025 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through 2.2.12.
Title WordPress JetTabs plugin <= 2.2.12 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crocoblock Jettabs
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:28.744Z

Reserved: 2025-12-19T10:16:41.921Z

Link: CVE-2025-68499

cve-icon Vulnrichment

Updated: 2025-12-30T18:48:47.028Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T00:15:52.583

Modified: 2026-04-23T15:35:55.467

Link: CVE-2025-68499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:15:28Z

Weaknesses