Description
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JetElements For Elementor plugin contains a contributor‑level cross‑site scripting flaw in any release up to version 2.9.1.1. The weakness, classified as CWE‑79, lets an attacker supply malicious JavaScript through an unfiltered input field, which is then rendered on pages accessed by visitors. Such injection can facilitate defacement, cookie theft, or session hijacking, thereby compromising the confidentiality and integrity of the website and its users.

Affected Systems

WordPress sites that incorporate the JetElements For Elementor plugin from Crocoblock (Jetimpex Inc.) and are running version 2.9.1.1 or older are vulnerable. No other products or higher versions are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low probability of exploitation at the time of analysis. The vulnerability is not present in the CISA KEV catalog. An attacker would need access to the contributor or content‑submission interface to inject the payload; if such a channel exists, the impact could be significant, but overall risk remains moderate due to the low likelihood of exploitation.

Generated by OpenCVE AI on August 3, 2026 at 22:07 UTC.

Remediation

Vendor Solution

Update the WordPress JetElements For Elementor Plugin to the latest available version (at least 2.9.1.2).


OpenCVE Recommended Actions

  • Update the JetElements For Elementor plugin to version 2.9.1.2 or later
  • Disable or uninstall the JetElements For Elementor plugin if it is not required for site functionality
  • Review existing content for injected scripts and remove any detected XSS payloads

Generated by OpenCVE AI on August 3, 2026 at 22:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock
Crocoblock jetelements For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Crocoblock
Crocoblock jetelements For Elementor
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
Title WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crocoblock Jetelements For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:45:22.492Z

Reserved: 2026-07-22T08:53:23.246Z

Link: CVE-2026-65465

cve-icon Vulnrichment

Updated: 2026-07-23T14:45:19.197Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:39.090

Modified: 2026-07-23T15:17:58.543

Link: CVE-2026-65465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')