CVE-2026-93618: WordPress JetTricks plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS.
This issue affects JetTricks: from n/a through 2.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetTricks Pluginto a version that resolves this vulnerability.Fixed in 2.0.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and user interaction. The attack can be performed over the network with low attack complexity.
What impact could successful exploitation have?
The vulnerability is a stored XSS issue, so attacker-controlled script could be saved and later executed in another user's browser. The CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed.
Which JetTricks versions are affected?
JetTricks versions through 2.0.1 are affected. The available data does not identify a fixed version.