CVE-2026-66572: WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2026
·Updated
Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.
Affected Software
1 affected component
JetBlog<=2.4.10
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetBlog pluginto a version that resolves this vulnerability.Fixed in 2.4.10.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level privileges in WordPress. The attack can be performed over the network with low complexity, but requires a user to interact with attacker-controlled content.
2
What versions are affected?
JetBlog versions up to and including 2.4.10 are affected.
3
What is the potential impact?
Successful exploitation can allow cross-site scripting in a context that affects a different security scope, with low potential impact to confidentiality, integrity, and availability.