Impact
The vulnerability is a contributor‑based Injected Cross Site Scripting flaw in JetElements For Elementor, where unsanitized input from user‑generated content allows the execution of arbitrary JavaScript in browsers that load affected pages. An attacker who can submit or edit content can inject malicious scripts that run within the context of visitors’ browsers, potentially stealing cookies, session tokens, or performing phishing or defacement attacks.
Affected Systems
WordPress sites that have the JetElements For Elementor plugin installing versions 2.9.2.1 or earlier, produced by Crocoblock / Jetimpex Inc. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity. The estimated EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is likely achievable through the normal content submission or editing interface, meaning an attacker who can become a contributor or who can force a user with contributor rights to submit malicious markup can trigger the flaw. The attack vector is likely remote via the web interface, and no elevated privileges beyond those required for content creation are strictly necessary.
OpenCVE Enrichment