Impact
The vulnerability arises from insufficient input sanitization and output escaping in Jeg Kit for Elementor, enabling an attacker to save malicious JavaScript in a comment. When the targeted post renders a legitimate Countdown widget, the front‑end script enqueues and initializes on any matching DOM element, including forged widget markup stored within comments. Successful exploitation allows arbitrary script execution with the same privileges as the page visitor, compromising confidentiality and integrity of the site’s content and potentially facilitating phishing or credential theft.
Affected Systems
WordPress sites running Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress versions up to and including 3.2.16 are affected. Any installation of the plugin that contains the Countdown widget and accepts comments is vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity condition, while the EPSS score of less than 1% suggests low current exploitation activity. The vulnerability is remotely exploitable by unauthenticated users who can comment on posts that contain a Countdown widget; no additional privileges or network access are required. The vulnerability is not listed in CISA’s KEV catalog, but if exploited it could enable widespread cross‑site scripting attacks on the site’s visitor base.
OpenCVE Enrichment