Description
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the targeted post also renders a legitimate Jeg Kit Countdown widget, which causes the countdown frontend script to be enqueued and to initialize on any matching DOM element — including forged widget markup stored in comments.
Published: 2026-09-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that allows unauthenticated attackers to inject and execute arbitrary web scripts on pages rendered to target users
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from insufficient input sanitization and output escaping in Jeg Kit for Elementor, enabling an attacker to save malicious JavaScript in a comment. When the targeted post renders a legitimate Countdown widget, the front‑end script enqueues and initializes on any matching DOM element, including forged widget markup stored within comments. Successful exploitation allows arbitrary script execution with the same privileges as the page visitor, compromising confidentiality and integrity of the site’s content and potentially facilitating phishing or credential theft.

Affected Systems

WordPress sites running Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress versions up to and including 3.2.16 are affected. Any installation of the plugin that contains the Countdown widget and accepts comments is vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high‑severity condition, while the EPSS score of less than 1% suggests low current exploitation activity. The vulnerability is remotely exploitable by unauthenticated users who can comment on posts that contain a Countdown widget; no additional privileges or network access are required. The vulnerability is not listed in CISA’s KEV catalog, but if exploited it could enable widespread cross‑site scripting attacks on the site’s visitor base.

Generated by OpenCVE AI on September 19, 2026 at 19:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • If an immediate update is not possible, disable the Countdown widget on all posts that accept comments, or remove it entirely from the affected pages.
  • Restrict comment posting to authenticated users and enable comment moderation so that any user‑generated content is reviewed before display.
  • Apply a general input sanitization rule for comment fields to escape HTML and JavaScript before storing them in the database.

Generated by OpenCVE AI on September 19, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Jegtheme
Jegtheme jeg Kit For Elementor – Powerful Addons For Elementor, Widgets & Templates For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Jegtheme
Jegtheme jeg Kit For Elementor – Powerful Addons For Elementor, Widgets & Templates For Wordpress
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the targeted post also renders a legitimate Jeg Kit Countdown widget, which causes the countdown frontend script to be enqueued and to initialize on any matching DOM element — including forged widget markup stored in comments.
Title Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Jegtheme Jeg Kit For Elementor – Powerful Addons For Elementor, Widgets & Templates For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T19:08:34.831Z

Reserved: 2026-07-30T15:58:56.596Z

Link: CVE-2026-18405

cve-icon Vulnrichment

Updated: 2026-09-18T19:08:30.742Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T10:17:06.310

Modified: 2026-09-18T20:17:10.207

Link: CVE-2026-18405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')