CVE-2025-54749: WordPress JetProductGallery Plugin <= 2.2.0.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProductGallery allows Stored XSS. This issue affects JetProductGallery: from n/a through 2.2.0.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProductGallery jet-woo-product-gallery allows Stored XSS.This issue affects JetProductGallery: from n/a through <= 2.2.0.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54749?
CVE-2025-54749 is classified as a medium-severity Stored Cross-site Scripting (XSS) vulnerability affecting certain versions of the Crocoblock JetProductGallery.
How do I fix CVE-2025-54749?
To fix CVE-2025-54749, update Crocoblock JetProductGallery to a version higher than 2.2.0.2.
What are the potential impacts of CVE-2025-54749?
Exploiting CVE-2025-54749 can allow attackers to execute arbitrary scripts in the context of the user's browser, leading to data theft or session hijacking.
Which versions of the software are affected by CVE-2025-54749?
CVE-2025-54749 affects Crocoblock JetProductGallery versions up to and including 2.2.0.2.
Is CVE-2025-54749 a common vulnerability?
CVE-2025-54749 is a known vulnerability in web applications, particularly within plugins like JetProductGallery, which makes it crucial for users to remain vigilant.