CVE-2025-53996: WordPress JetSearch plugin <= 3.5.10.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch allows Stored XSS. This issue affects JetSearch: from n/a through 3.5.10.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows Stored XSS.This issue affects JetSearch: from n/a through <= 3.5.10.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53996?
CVE-2025-53996 is a high severity vulnerability due to its nature of allowing stored cross-site scripting (XSS).
How do I fix CVE-2025-53996?
To fix CVE-2025-53996, update the JetSearch plugin to a version beyond 3.5.10.1 that addresses the XSS vulnerability.
What type of vulnerability is CVE-2025-53996?
CVE-2025-53996 is classified as a Cross-site Scripting (XSS) vulnerability affecting the JetSearch plugin.
Which versions of JetSearch are affected by CVE-2025-53996?
CVE-2025-53996 affects JetSearch versions from n/a through 3.5.10.1.
What potential impact does CVE-2025-53996 have on users?
The impact of CVE-2025-53996 includes the possibility for attackers to execute malicious scripts in the context of users’ browsers, potentially leading to data theft or account compromise.