Impact
The JetElements For Elementor plugin contains a contributor‑level cross‑site scripting flaw in any release up to version 2.9.1.1. The weakness, classified as CWE‑79, lets an attacker supply malicious JavaScript through an unfiltered input field, which is then rendered on pages accessed by visitors. Such injection can facilitate defacement, cookie theft, or session hijacking, thereby compromising the confidentiality and integrity of the website and its users.
Affected Systems
WordPress sites that incorporate the JetElements For Elementor plugin from Crocoblock (Jetimpex Inc.) and are running version 2.9.1.1 or older are vulnerable. No other products or higher versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation at the time of analysis. The vulnerability is not present in the CISA KEV catalog. An attacker would need access to the contributor or content‑submission interface to inject the payload; if such a channel exists, the impact could be significant, but overall risk remains moderate due to the low likelihood of exploitation.
OpenCVE Enrichment