Impact
The JetWidgets For Elementor plugin for WordPress contains a stored cross‑site scripting flaw in its Image Comparison and Subscribe widgets. The flaw occurs because user‑supplied attributes are not properly sanitized or escaped, allowing an authenticated attacker with contributor-level access or higher to inject arbitrary JavaScript that will execute whenever a page containing the widget is viewed. This vulnerability is classified as CWE‑79 and permits the attacker to introduce malicious scripts into the site’s pages.
Affected Systems
Affected systems are WordPress sites that have the JetMonsters JetWidgets For Elementor plugin deployed, specifically all releases up to and including version 1.0.20. The vulnerability impacts the Image Comparison and Subscribe widget components, which can be placed anywhere on a page by users with contributor or higher privileges.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires authenticated access at the contributor level or higher; the attacker must create or manipulate widget attributes that are then stored in the database and rendered on page load.
OpenCVE Enrichment