CVE-2025-49933: WordPress JetBlog plugin <= 2.4.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows Reflected XSS.This issue affects JetBlog: from n/a through <= 2.4.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49933?
CVE-2025-49933 has been classified as a high-severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-49933?
To resolve CVE-2025-49933, update CrocoBlock JetBlog to version 2.4.5 or later.
What software is affected by CVE-2025-49933?
CVE-2025-49933 affects CrocoBlock JetBlog and WordPress JetBlog versions up to and including 2.4.4.
What type of vulnerability is CVE-2025-49933?
CVE-2025-49933 is a cross-site scripting (XSS) vulnerability that allows attackers to execute scripts in the context of a user’s browser.
Can CVE-2025-49933 be exploited by remote attackers?
Yes, CVE-2025-49933 can be exploited by attackers who can craft malicious links that target vulnerable installations.