Impact
A reflected Cross‑Site Scripting vulnerability exists in Crocoblock JetEngine where user input is not properly neutralized before being echoed in the web page. This flaw can allow an attacker to inject malicious scripts into a site that are executed by users who view the affected pages, potentially leading to session hijacking, cookie theft, defacement, or the execution of arbitrary JavaScript in the context of the victim’s browser.
Affected Systems
The flaw affects all installations of the JetEngine WordPress plugin for the Crocoblock platform with versions up to and including 3.8.14.2. Any WordPress site using this plugin within that version range is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity assessment, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires the ability to send or embed a crafted payload that is reflected back in the browser; it is likely a classic reflected XSS vector that does not need authentication. Given the lack of an exploitation probability metric, the threat depends largely on the presence of exposed or public entry points where the plugin processes user input.
OpenCVE Enrichment