Impact
Crocoblock JetElements For Elementor contains a stored XSS flaw where malicious input is incorrectly neutralized during web page rendering. This weakness, identified as CWE-79, allows an attacker to inject and execute arbitrary JavaScript in the context of victims browsing a site that uses the plugin.
Affected Systems
The vulnerability is present in JetElements For Elementor versions 2.7.8 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 percent suggests that exploitation is unlikely but still feasible. The flaw is not listed in the CISA KEV catalog. The likely attack vector involves an attacker supplying malicious content through the plugin’s input fields, which is then stored and rendered without proper sanitization when the page loads.
OpenCVE Enrichment