Junglewise Threat Intelligence

CVE-2026-66572: Crocoblock JetBlog cross-site scripting in contributor form

CVE-2026-66572 · Severity: medium · CVSS 6.5 · Published 2026-09-17

Vendors: Crocoblock.

Executive brief

JetBlog is a WordPress plugin for creating and managing blog content. The plugin contains a cross-site scripting (XSS) vulnerability in its contributor interface that allows an authenticated contributor to inject malicious scripts. If exploited, attackers could steal visitor data, hijack user accounts, or deface the website.

Technical details

JetBlog versions up to 2.4.10 are vulnerable to stored or reflected cross-site scripting (XSS) in the contributor area. The vulnerability allows authenticated users with contributor privileges to inject unvalidated input that is executed in the context of other users' browsers. Exploitation requires user interaction (e.g., a contributor clicking a malicious link or submitting a crafted form). An attacker with contributor access can inject JavaScript to steal session tokens, modify page content, or redirect users to phishing sites. The vulnerability has been patched in version 2.4.10.1 and later.

Affected products

  • Crocoblock JetBlog <=2.4.10

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Version 2.4.10.1 and later

References

Related threats