Description
Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JetReviews plugin for WordPress contains a cross‑site scripting vulnerability, classified as CWE‑79, affecting all releases up to 3.0.0.1. The description does not provide details on the trigger or input source, but XSS can allow an attacker to execute arbitrary JavaScript in the context of a user’s browser, potentially compromising confidentiality, integrity, or availability of that user’s session.

Affected Systems

The JetReviews plugin for WordPress, distributed by Crocoblock and Jetimpex Inc., is affected. Versions up to and including 3.0.0.1 are identified with a cross‑site scripting vulnerability. No specific attack vector or payload details are provided in the description. The vulnerability is classified as CWE‑79.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity for the XSS vulnerability. The EPSS score of < 1% suggests a very low probability of exploitation being documented. The description does not specify the exact attack vector or the specific context in which malicious scripts might be injected or executed. However, cross‑site scripting can lead to compromise of confidentiality, integrity, or availability of affected user sessions when arbitrary scripts are executed in the user’s browser.

Generated by OpenCVE AI on July 21, 2026 at 11:53 UTC.

Remediation

Vendor Solution

Update the WordPress JetReviews Plugin to the latest available version (at least 3.0.0.2).


OpenCVE Recommended Actions

  • Apply the latest version of JetReviews (3.0.0.2 or newer).
  • Implement a strict Content Security Policy to reduce the impact of injected scripts if an immediate upgrade is not possible.
  • Inspect existing review content for malicious scripts, and sanitize or delete them.

Generated by OpenCVE AI on July 21, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock. Jetimpex Inc.
Crocoblock. Jetimpex Inc. jetreviews
Wordpress
Wordpress wordpress
Vendors & Products Crocoblock. Jetimpex Inc.
Crocoblock. Jetimpex Inc. jetreviews
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
Title WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crocoblock. Jetimpex Inc. Jetreviews
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:35:43.161Z

Reserved: 2026-06-24T12:45:36.888Z

Link: CVE-2026-57354

cve-icon Vulnrichment

Updated: 2026-07-02T14:35:39.721Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')