WordPress JetBlocks For Elementor Plugin <= 1.3.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-48756

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
14 December 2023

Summary

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Crocoblock JetBlocks plugin for Elementor. This vulnerability allows malicious actors to inject arbitrary web scripts into pages viewed by unsuspecting users. When users interact with affected pages, these scripts can be executed, potentially leading to data theft or session hijacking. The affected versions of JetBlocks for Elementor extend from n/a through 1.3.8. Website administrators are advised to update to the latest version to mitigate this risk.

Affected Version(s)

JetBlocks For Elementor <= 1.3.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.