Cross-site Scripting Vulnerability in Crocoblock JetSearch
CVE-2025-53996
6.5MEDIUM
What is CVE-2025-53996?
A Cross-site Scripting (XSS) vulnerability exists in the Crocoblock JetSearch plugin, allowing attackers to inject malicious scripts that may be executed by users accessing affected web pages. This vulnerability can enable stored XSS, which poses a significant security risk for websites utilizing JetSearch versions from n/a up to 3.5.10.1. It's essential for administrators to implement prompt updates and validate input to mitigate potential exploits.
Affected Version(s)
JetSearch <= 3.5.10.1