Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.19.
Published: 2025-07-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Crocoblock JetBlocks for Elementor includes a stored XSS vulnerability that arises from improper input sanitization during web page generation. An attacker who can inject malicious payloads into content stored by the plugin can later cause client‑side script execution when the affected page is viewed by other users. This can be used to steal session data, deface sites, or perform other malicious client‑side actions. The weakness is classified as CWE‑79.

Affected Systems

WordPress installations that have installed the JetBlocks for Elementor plugin in any version up to and including 1.3.19 are affected. The plugin, maintained by Crocoblock, is commonly added to provide custom blocks for the Elementor page builder. Administrators of sites running WordPress with this plugin should verify their installed version and consider upgrading.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity public vulnerability. The EPSS score is listed as less than 1%, implying a low probability of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. Attack vectors for stored XSS typically require the attacker to have sufficient privileges to insert content—such as being an administrator or a user with block management rights—after which the malicious script will execute for any user who views the relevant page. Because the vulnerability is stored, once the payload is inserted it remains until removed, making it persistent across users.

Generated by OpenCVE AI on April 30, 2026 at 09:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBlocks for Elementor to the latest patched version (1.3.20 or higher).
  • If an upgrade is not feasible, remove or disable the plugin from the site until a fix is available.
  • Implement a Content Security Policy (CSP) that restricts script execution to trusted sources to mitigate the impact of any remaining XSS vectors.

Generated by OpenCVE AI on April 30, 2026 at 09:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21689 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor allows Stored XSS. This issue affects JetBlocks For Elementor: from n/a through 1.3.19.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor allows Stored XSS. This issue affects JetBlocks For Elementor: from n/a through 1.3.19. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.19.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 18 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00031}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor allows Stored XSS. This issue affects JetBlocks For Elementor: from n/a through 1.3.19.
Title WordPress JetBlocks For Elementor plugin <= 1.3.19 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:27.116Z

Reserved: 2025-07-16T08:51:03.832Z

Link: CVE-2025-53989

cve-icon Vulnrichment

Updated: 2025-07-18T14:53:24.390Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:26.723

Modified: 2026-04-23T15:32:39.997

Link: CVE-2025-53989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:00:16Z

Weaknesses