CVE-2025-49932: WordPress JetBlog plugin <= 2.4.4.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows Stored XSS.This issue affects JetBlog: from n/a through <= 2.4.4.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49932?
CVE-2025-49932 is classified as a high severity vulnerability due to its potential for allowing stored cross-site scripting (XSS).
How do I fix CVE-2025-49932?
To remediate CVE-2025-49932, update the JetBlog plugin to the latest version beyond 2.4.4.1 to eliminate the vulnerability.
What is the impact of CVE-2025-49932?
The impact of CVE-2025-49932 includes the potential execution of malicious scripts in users' browsers, which can compromise user data and website integrity.
Is my version affected by CVE-2025-49932?
If you are using CrocoBlock JetBlog version 2.4.4.1 or earlier, your version is affected by CVE-2025-49932.
What types of exploits can occur due to CVE-2025-49932?
Exploits due to CVE-2025-49932 can lead to data theft, session hijacking, and defacement of affected web pages.