Description
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Immediate persistence without moderator approval is possible when the attacker submits from an email address with at least one previously approved comment, though the widened allowlist bypasses sanitization regardless of approval status.
Published: 2026-10-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting
Action: Apply Updated Plugin
AI Analysis

Impact

The Jeg Kit for Elementor plugin is vulnerable to a stored cross‑site scripting flaw that is triggered via a comment submission. Because the plugin does not properly sanitize or escape user input before storing it, an unauthenticated attacker can inject arbitrary JavaScript. When a user later views the page containing the comment, the injected script executes in that user’s browser, potentially leaking credentials, defacing content, or hijacking the session. This flaw is a classic injection weakness identified as CWE‑79.

Affected Systems

Relying WordPress installations running Jeg Kit for Elementor version 3.2.19 or earlier. The plugin is provided by jegtheme and includes powerful addons, widgets, and templates for Elementor. Versions through 3.2.19 are affected; information regarding newer releases does not confirm a fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.4, indicating moderate impact. There is no EPSS score available, and the flaw is not listed in the CISA KEV catalog, suggesting limited public exploitation yet. Because the attack does not require authentication, any visitor capable of posting a comment can inject malicious payloads. The flaw achieves persistence without moderator approval when the attacker uses an email address that has already earned an approved comment, and the allowlist expansion removes the approval gate entirely. In environments where comments on plugin‑associated pages are publicly accessible, the risk escalates.

Generated by OpenCVE AI on October 3, 2026 at 03:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Jeg Kit for Elementor to the latest available version, as it may contain a fix for the sanitization issue.
  • If an upgrade cannot be performed immediately, disable or remove the comment posting feature for pages that utilise the plugin until a patch is applied.
  • Implement or enforce strict WordPress comment moderation and sanitization settings to verify that all user‑generated content is escaped before storage and display.

Generated by OpenCVE AI on October 3, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Immediate persistence without moderator approval is possible when the attacker submits from an email address with at least one previously approved comment, though the widened allowlist bypasses sanitization regardless of approval status.
Title Jeg Kit for Elementor <= 3.2.19 - Unauthenticated Stored Cross-Site Scripting via Comment
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:47.431Z

Reserved: 2026-09-25T13:35:59.335Z

Link: CVE-2026-100180

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:50.519Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:36.713

Modified: 2026-10-03T16:16:31.010

Link: CVE-2026-100180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')