CVE-2025-68499: WordPress JetTabs plugin <= 2.2.12 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through 2.2.12.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68499?
CVE-2025-68499 has been classified as a high-severity vulnerability due to its potential for allowing DOM-based cross-site scripting (XSS).
How do I fix CVE-2025-68499?
To fix CVE-2025-68499, update the Crocoblock JetTabs plugin to version 2.2.13 or greater, which addresses the XSS vulnerability.
What type of attack can be executed using CVE-2025-68499?
CVE-2025-68499 can be exploited for cross-site scripting (XSS) attacks, allowing malicious scripts to be executed in the context of a user's browser.
Which versions of JetTabs are affected by CVE-2025-68499?
CVE-2025-68499 affects all versions of JetTabs from n/a through 2.2.12.
What is the nature of the vulnerability in CVE-2025-68499?
CVE-2025-68499 is an improper neutralization of input during web page generation, leading to cross-site scripting vulnerabilities.