Impact
The vulnerability is a contributor‑level cross‑site scripting flaw that occurs when the JetSearch plugin processes content from a contributor. An attacker can inject malicious scripts into pages served by the plugin. Because the scripts run in the context of a user’s browser, the attacker could steal session tokens, perform defacement, or execute arbitrary client‑side code. The weakness stems from improper output encoding and falls under CWE‑79.
Affected Systems
The flaw affects the JetSearch plugin supplied by Crocoblock and Jetimpex Inc. The affected release is any JetSearch version 3.6.3 or earlier. The recommended fixed release is 3.6.3.1 or any later version.
Risk and Exploitability
With a CVSS score of 6.5, the flaw presents moderate severity. No EPSS data is provided, and the vulnerability has not been listed in the CISA KEV catalog. The likely attack vector is a malicious contributor who can add data to the site via the plugin; the plugin is then used to serve that data to other website visitors.
OpenCVE Enrichment