Impact
The JetReviews plugin for WordPress contains a cross‑site scripting vulnerability, classified as CWE‑79, affecting all releases up to 3.0.0.1. The description does not provide details on the trigger or input source, but XSS can allow an attacker to execute arbitrary JavaScript in the context of a user’s browser, potentially compromising confidentiality, integrity, or availability of that user’s session.
Affected Systems
The JetReviews plugin for WordPress, distributed by Crocoblock and Jetimpex Inc., is affected. Versions up to and including 3.0.0.1 are identified with a cross‑site scripting vulnerability. No specific attack vector or payload details are provided in the description. The vulnerability is classified as CWE‑79.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity for the XSS vulnerability. The EPSS score of <1% suggests a very low probability of documented exploitation. This issue is not listed in the CISA KEV catalog, meaning no known active exploitation. The vulnerability permits an attacker to inject and execute arbitrary JavaScript when a subscriber views content processed by JetReviews, potentially compromising confidentiality, integrity, or availability of that user's session. No exploitation requires privileged access or server compromise; it is a client‑side weakness.
OpenCVE Enrichment