Description
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a contributor‑level cross‑site scripting flaw that occurs when the JetSearch plugin processes content from a contributor. An attacker can inject malicious scripts into pages served by the plugin. Because the scripts run in the context of a user’s browser, the attacker could steal session tokens, perform defacement, or execute arbitrary client‑side code. The weakness stems from improper output encoding and falls under CWE‑79.

Affected Systems

The flaw affects the JetSearch plugin supplied by Crocoblock and Jetimpex Inc. The affected release is any JetSearch version 3.6.3 or earlier. The recommended fixed release is 3.6.3.1 or any later version.

Risk and Exploitability

With a CVSS score of 6.5, the flaw presents moderate severity. No EPSS data is provided, and the vulnerability has not been listed in the CISA KEV catalog. The likely attack vector is a malicious contributor who can add data to the site via the plugin; the plugin is then used to serve that data to other website visitors.

Generated by OpenCVE AI on September 17, 2026 at 22:13 UTC.

Remediation

Vendor Solution

Update the WordPress JetSearch Plugin to the latest available version (at least 3.6.3.1).


OpenCVE Recommended Actions

  • Update the JetSearch plugin to version 3.6.3.1 or later.
  • If a patch is not immediately available, remove or disable the JetSearch plugin until the update is applied.
  • Restrict contributor permissions to prevent malicious content from being introduced, or enable a content‑filtering plugin that sanitizes user input.

Generated by OpenCVE AI on September 17, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
Title WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T14:21:54.197Z

Reserved: 2026-07-27T13:59:59.781Z

Link: CVE-2026-66577

cve-icon Vulnrichment

Updated: 2026-09-19T14:16:48.771Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:16.340

Modified: 2026-09-19T15:17:00.393

Link: CVE-2026-66577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')