VYPR
Medium severity6.4NVD Advisory· Published Aug 16, 2024· Updated Apr 15, 2026

CVE-2024-7136

CVE-2024-7136

Description

Stored XSS in JetSearch plugin for WordPress allows authenticated attackers with Contributor-level access to inject arbitrary scripts via the 'id' parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in JetSearch plugin for WordPress allows authenticated attackers with Contributor-level access to inject arbitrary scripts via the 'id' parameter.

Vulnerability

Overview

The JetSearch plugin for WordPress, developed by Crocoblock, is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 3.5.2. The flaw resides in insufficient input sanitization and output escaping of the 'id' parameter, allowing authenticated attackers to inject arbitrary web scripts that execute when a user accesses a compromised page [1].

Exploitation

Prerequisites

An attacker must have at least Contributor-level access to the WordPress site. The vulnerability is triggered by supplying a malicious payload in the 'id' parameter, which is then stored and rendered unsafely. No additional authentication or network position is required beyond the initial contributor account.

Impact

Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of any user viewing the affected page. This can lead to session hijacking, defacement, or redirection to malicious sites, compromising the integrity and confidentiality of the WordPress installation.

Mitigation

Crocoblock has not yet released a patched version as of the publication date. Users are advised to restrict Contributor-level access or apply input validation and output escaping manually until an update is available.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.