
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68495 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Crocoblock JetEngine WordPress plugin, affecting all versions up to and including 3.8.0. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). It was reported on November 30, 2025, by researcher "Bonds" via Patchstack's Active VDP program, and publicly disclosed on February 11, 2026. The vulnerability carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and is specifically a reflected XSS variant. Malicious input supplied via HTTP request parameters is echoed back in the server's response without adequate sanitization or encoding, allowing injected JavaScript to execute in the victim's browser. The attack vector is network-based, requires no authentication (unauthenticated attacker), but does require user interaction — a privileged user must click a crafted link or visit a malicious page for the payload to execute. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of site visitors to malicious content. Because the scope is changed, the impact extends beyond the plugin itself to the broader WordPress environment and any authenticated users who interact with the crafted link (Patchstack).
No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2025-68495 at this time. The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation in the wild. However, Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
https://target-site.com/?jet-engine-param=<script>malicious_code</script>).%3Cscript%3E, onerror=, onload=) in query parameters.The vendor Crocoblock has released JetEngine version 3.8.1, which patches this vulnerability. All users should update the JetEngine plugin to version 3.8.1 or later immediately. As an interim measure, Patchstack has issued a virtual patch (WAF rule) for its subscribers to block exploitation attempts until the plugin is updated. Site administrators unable to update immediately should consider temporarily deactivating the plugin and consulting their hosting provider (Patchstack).
Patchstack, which coordinated the responsible disclosure through its Active VDP program, classified this as a medium-priority vulnerability and noted that reflected XSS flaws of this type are frequently leveraged in mass-exploit campaigns against WordPress sites. No significant vendor statements beyond the patch release or notable independent researcher commentary have been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."