Junglewise Threat Intelligence

CVE-2026-57354: Crocoblock JetReviews Cross Site Scripting

CVE-2026-57354 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Vendors: Crocoblock.

Executive brief

JetReviews, a WordPress plugin used for adding review and rating systems to websites, contains a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts. If a site administrator or another visitor views the affected content, these scripts could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information. This vulnerability could be used to deface the site or redirect users to malicious websites.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Crocoblock JetReviews plugin for WordPress (versions 3.0.0.1 and below). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Subscriber-level authentication can inject malicious HTML or JavaScript payloads into review-related fields. The exploit requires a victim (such as an administrator) to interact with the affected page or perform a specific action for the script to execute. Successful exploitation allows for session hijacking, unauthorized administrative actions, or site defacement. The issue is resolved in version 3.0.0.2.

Affected products

  • Crocoblock (Jetimpex Inc.) JetReviews <= 3.0.0.1

Timeline

  • 2026-05-18: disclosed: Reported by Austin Ginder
  • 2026-07-01: patched: Version 3.0.0.2 released
  • 2026-07-02: advisory

References

Related threats