Impact
The Jeg Kit for Elementor plugin is vulnerable to a stored cross‑site scripting flaw that is triggered via a comment submission. Because the plugin does not properly sanitize or escape user input before storing it, an unauthenticated attacker can inject arbitrary JavaScript. When a user later views the page containing the comment, the injected script executes in that user’s browser, potentially leaking credentials, defacing content, or hijacking the session. This flaw is a classic injection weakness identified as CWE‑79.
Affected Systems
Relying WordPress installations running Jeg Kit for Elementor version 3.2.19 or earlier. The plugin is provided by jegtheme and includes powerful addons, widgets, and templates for Elementor. Versions through 3.2.19 are affected; information regarding newer releases does not confirm a fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating moderate impact. There is no EPSS score available, and the flaw is not listed in the CISA KEV catalog, suggesting limited public exploitation yet. Because the attack does not require authentication, any visitor capable of posting a comment can inject malicious payloads. The flaw achieves persistence without moderator approval when the attacker uses an email address that has already earned an approved comment, and the allowlist expansion removes the approval gate entirely. In environments where comments on plugin‑associated pages are publicly accessible, the risk escalates.
OpenCVE Enrichment