Executive brief
JetElements is a popular add-on for the Elementor website builder on WordPress that provides additional design widgets. A security flaw allows users with 'Contributor' level access to inject malicious scripts into website pages. If an administrator or site visitor views the affected page, these scripts could redirect users to malicious sites, display unauthorized advertisements, or potentially compromise user sessions.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the JetElements For Elementor plugin for WordPress (versions <= 2.9.1.1). The issue stems from improper neutralization of input during web page generation (CWE-79). An attacker with Contributor-level privileges can inject malicious HTML or JavaScript payloads into the site's content. Successful exploitation requires a victim (such as an administrator) to interact with the affected page or perform a specific action like clicking a link. This can lead to unauthorized script execution in the context of the victim's browser, potentially resulting in session hijacking or site defacement. The vulnerability is addressed in version 2.9.1.2.
Affected products
- Crocoblock. Jetimpex Inc. JetElements For Elementor <= 2.9.1.1
Timeline
- 2026-07-02: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: advisory: NVD advisory published
- 2026-07-23: patched: Version 2.9.1.2 released to address the issue