CVE-2025-54687: WordPress JetTabs Plugin plugin <= 2.2.9.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS. This issue affects JetTabs: from n/a through 2.2.9.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.9.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54687?
CVE-2025-54687 is classified as a high-severity vulnerability due to its potential for DOM-Based XSS attacks.
How do I fix CVE-2025-54687?
To address CVE-2025-54687, users should update Crocoblock JetTabs to version 2.2.9.2 or later, which patches the vulnerability.
What types of attacks can exploit CVE-2025-54687?
CVE-2025-54687 can be exploited to perform cross-site scripting (XSS) attacks, compromising user data and web security.
Which versions of JetTabs are affected by CVE-2025-54687?
CVE-2025-54687 affects JetTabs versions up to and including 2.2.9.1.
Who is impacted by CVE-2025-54687?
Users of the Crocoblock JetTabs plugin, specifically those running affected versions on their WordPress sites, are impacted by CVE-2025-54687.