Description
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Patch Now
AI Analysis

Impact

The plugin contains a contributor‑originated Cross Site Scripting flaw that allows attackers to inject malicious script into web pages served by WordPress sites using JetBlocks for Elementor. The vulnerability can be triggered when a malicious user submits input that is not properly sanitized, potentially leading to session hijacking, cookie theft, defacement, or the execution of arbitrary code in the victim’s browser. This flaw correlates with CWE‑79, a classic user‑input sanitization weakness.

Affected Systems

The flaw affects the WordPress JetBlocks for Elementor plugin version 1.5.2 and earlier. The plugin is distributed by Crocoblock and Jetimpex Inc. Users running these versions on any WordPress installation are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium‑to‑high severity vulnerability. The EPSS score is not available, but the existence of the flaw in a popular plugin suggests a non‑negligible exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw by submitting crafted input through web pages or forms, generally requiring anonymous or low‑privilege access. Once executed, the malicious script runs in the context of the victim’s browser, facilitating cookie theft, defacement, or further session‑level attacks.

Generated by OpenCVE AI on September 17, 2026 at 21:01 UTC.

Remediation

Vendor Solution

Update the WordPress JetBlocks For Elementor Plugin to the latest available version (at least 1.5.2.1).


OpenCVE Recommended Actions

  • Upgrade to the latest JetBlocks for Elementor plugin (version 1.5.2.1 or newer) as soon as possible.
  • If an immediate upgrade is not feasible, remove or disable the JetBlocks for Elementor plugin from the WordPress installation to eliminate the attack surface.
  • Audit all user‑generated content in Elementor pages for proper sanitization and consider enabling a Web Application Firewall or security plugin that blocks or sanitizes script injection attempts.

Generated by OpenCVE AI on September 17, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Crocoblock
Crocoblock jetblocks For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Crocoblock
Crocoblock jetblocks For Elementor
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
Title WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crocoblock Jetblocks For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T14:39:34.318Z

Reserved: 2026-07-27T13:59:59.781Z

Link: CVE-2026-66576

cve-icon Vulnrichment

Updated: 2026-09-17T14:39:30.985Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:16.213

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-66576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')