Impact
The vulnerability allows an attacker to inject unsanitized JavaScript that is stored in JetTricks’ content fields. When visitors view the affected page, the payload executes in their browsers, potentially leading to cookie theft, session hijacking, defacement, or delivery of malware. The weakness stems from improper neutralization of input, a stored XSS flaw (CWE‑79).
Affected Systems
The JetTricks WordPress plugin, developed by Crocoblock (Jetimpex Inc.), is affected for all releases up to and including 2.0.1. Sites that have installed or enabled any of these versions are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS data is available and the issue is not listed in the CISA KEV catalogue. The likely attack vector requires an authenticated user with CMS editor privileges; such a user can submit malicious content that will persist and execute for all site visitors. Because the flaw is stored, a single injection can compromise every user until mitigated.
OpenCVE Enrichment