Impact
The plugin contains a contributor‑originated Cross Site Scripting flaw that allows attackers to inject malicious script into web pages served by WordPress sites using JetBlocks for Elementor. The vulnerability can be triggered when a malicious user submits input that is not properly sanitized, potentially leading to session hijacking, cookie theft, defacement, or the execution of arbitrary code in the victim’s browser. This flaw correlates with CWE‑79, a classic user‑input sanitization weakness.
Affected Systems
The flaw affects the WordPress JetBlocks for Elementor plugin version 1.5.2 and earlier. The plugin is distributed by Crocoblock and Jetimpex Inc. Users running these versions on any WordPress installation are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑to‑high severity vulnerability. The EPSS score is not available, but the existence of the flaw in a popular plugin suggests a non‑negligible exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw by submitting crafted input through web pages or forms, generally requiring anonymous or low‑privilege access. Once executed, the malicious script runs in the context of the victim’s browser, facilitating cookie theft, defacement, or further session‑level attacks.
OpenCVE Enrichment