CVE-2026-94667: WordPress JetReviews plugin <= 3.1.2 - Cross Site Scripting (XSS) vulnerability
Published Oct 9, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetReviews jet-reviews allows Stored XSS.This issue affects JetReviews: from n/a through 3.1.2.
Affected Software
1 affected component
Crocoblock JetReviews<=3.1.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetReviewsto a version that resolves this vulnerability.Fixed in 3.1.2.1
Event History
Oct 9, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
RemedyDescriptionSeverityWeakness