CVE · Medium

CVE-2025-53991 — JetTricks [jet-tricks] < 1.5.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-53991 JetTricks [jet-tricks] < 1.5.4.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.5.4.2 1.5.4.2 2025-07-16

CVE-2025-53991

The JetTricks plugin for WordPress has a security flaw affecting versions 1.5.4.1 and earlier, allowing malicious users with at least contributor privileges to embed malicious code into certain website pages, which would then run when visited by other users. This vulnerability stems from inadequate filtering of user input and insufficient protection against potentially hazardous scripts being displayed on the site. As a result, attackers can exploit this weakness to compromise the security of targeted websites.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.