Impact
Contributor Cross Site Scripting (XSS) exists in JetBlog plugin versions up to 2.4.10. The vulnerability allows contributors to insert malicious scripts into content that is shown to site visitors.
Affected Systems
WordPress installations that use the Crocoblock JetBlog plugin version 2.4.10 or earlier are affected. The plugin is distributed by Crocoblock and Jetimpex Inc. and must be upgraded to at least 2.4.10.1 to eliminate the flaw.
Risk and Exploitability
The CVSS score value of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment