Cross-Site Scripting Vulnerability in CrocoBlock JetWooBuilder Plugin
CVE-2025-49928 
6.5MEDIUM
What is CVE-2025-49928?
The CrocoBlock JetWooBuilder plugin for WordPress is susceptible to a DOM-Based Cross-Site Scripting (XSS) vulnerability. This flaw arises from improper handling of input during web page generation, potentially allowing attackers to inject malicious scripts that would be executed in the context of the user's browser. The issue affects users of JetWooBuilder from its initial release until version 2.1.20. To mitigate this risk, users should update to the latest version of the plugin and implement proper input validation practices.
Affected Version(s)
JetWooBuilder <= n/a