Impact
The JetReviews plugin for WordPress contains a cross‑site scripting vulnerability, classified as CWE‑79, affecting all releases up to 3.0.0.1. The description does not provide details on the trigger or input source, but XSS can allow an attacker to execute arbitrary JavaScript in the context of a user’s browser, potentially compromising confidentiality, integrity, or availability of that user’s session.
Affected Systems
The JetReviews plugin for WordPress, distributed by Crocoblock and Jetimpex Inc., is affected. Versions up to and including 3.0.0.1 are identified with a cross‑site scripting vulnerability. No specific attack vector or payload details are provided in the description. The vulnerability is classified as CWE‑79.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity for the XSS vulnerability. The EPSS score of < 1% suggests a very low probability of exploitation being documented. The description does not specify the exact attack vector or the specific context in which malicious scripts might be injected or executed. However, cross‑site scripting can lead to compromise of confidentiality, integrity, or availability of affected user sessions when arbitrary scripts are executed in the user’s browser.
OpenCVE Enrichment