Impact
The Jeg Kit for Elementor plugin stores malicious script code in the ‘sg_body_description’ field of the Image Box widget. This is a CWE‑79 vulnerability because the value is concatenated directly into an HTML body context without escaping, allowing a contributor‑level user to persist script payloads that execute for any visitor who views the affected page.
Affected Systems
WordPress installations running Jeg Kit for Elementor version 3.2.6 or earlier, provided by JegTheme.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with Contributor privileges, but any site visitor will execute any injected script when loading the compromised page.
OpenCVE Enrichment