Description
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (client‑side)
Action: Update Plugin
AI Analysis

Impact

The vulnerability is a contributor‑based Injected Cross Site Scripting flaw in JetElements For Elementor, where unsanitized input from user‑generated content allows the execution of arbitrary JavaScript in browsers that load affected pages. An attacker who can submit or edit content can inject malicious scripts that run within the context of visitors’ browsers, potentially stealing cookies, session tokens, or performing phishing or defacement attacks.

Affected Systems

WordPress sites that have the JetElements For Elementor plugin installing versions 2.9.2.1 or earlier, produced by Crocoblock / Jetimpex Inc. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate severity. The estimated EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is likely achievable through the normal content submission or editing interface, meaning an attacker who can become a contributor or who can force a user with contributor rights to submit malicious markup can trigger the flaw. The attack vector is likely remote via the web interface, and no elevated privileges beyond those required for content creation are strictly necessary.

Generated by OpenCVE AI on September 17, 2026 at 22:12 UTC.

Remediation

Vendor Solution

Update the WordPress JetElements For Elementor Plugin to the latest available version (at least 2.9.2.2).


OpenCVE Recommended Actions

  • Upgrade JetElements For Elementor to version 2.9.2.2 or later.
  • Restrict contributor and guest permissions so that only trusted users can publish or edit content that feeds the vulnerable fields.
  • Configure a site‑wide Content Security Policy to disallow inline scripts and restrict script sources, serving as a temporary workaround while awaiting a patch.

Generated by OpenCVE AI on September 17, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
Title WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T02:22:13.087Z

Reserved: 2026-07-27T13:59:59.781Z

Link: CVE-2026-66579

cve-icon Vulnrichment

Updated: 2026-09-19T02:22:08.630Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:16.653

Modified: 2026-09-19T03:17:14.923

Link: CVE-2026-66579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')