Impact
Contributor Cross‑Site Scripting (XSS) in JetTabs versions up to 2.3.3.1 allows untrusted input to be rendered as executable code in the browser. The vulnerability is categorized as CWE‑79 and can enable attackers to inject malicious JavaScript, potentially leading to defacement, credential theft, or session hijacking. The impact is confined to the front‑end web interface where the plugin outputs user‑supplied data.
Affected Systems
The affected product is the JetTabs WordPress plugin from Crocoblock (also known as Jetimpex Inc.) and is any installation running version 2.3.3.1 or earlier. No specific WordPress core versions are listed as affected, but all sites that have the plugin installed and are not updated beyond the stated version are vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity without accidental or environmental adjustments. Exploitability information via EPSS is not available, and the vulnerability is not included in CISA’s KEV catalog, suggesting no large‑scale exploitation has been reported. Because the flaw is an XSS flaw, the likely attack vector involves a web request that passes arbitrary script content into the plugin’s output, so attackers need only send crafted input through a publicly accessible front‑end endpoint. The risk is moderate for sites that expose the plugin without proper input sanitization, and it may affect any authenticated or unauthenticated user visiting the affected pages.
OpenCVE Enrichment