Executive brief
JetBlocks For Elementor is a WordPress plugin that provides page building blocks for the Elementor website builder. A cross-site scripting (XSS) vulnerability in versions up to 1.5.2 allows a malicious contributor to inject JavaScript code into pages, which could be used to steal visitor data, compromise user accounts, or deface website content. Exploitation requires a contributor-level or higher user role to click a malicious link or visit a crafted page.
Technical details
This is a cross-site scripting (XSS) vulnerability in JetBlocks For Elementor affecting versions up to and including 1.5.2. The vulnerability exists in a component accessible to contributor-level users and requires user interaction (such as clicking a malicious link or submitting a form) to trigger. An attacker with contributor privileges can inject malicious JavaScript that executes in the browsers of site visitors, potentially stealing session cookies, credentials, or performing unauthorized actions on behalf of victims. The vulnerability has been patched in version 1.5.2.1 and later.
Affected products
- Crocoblock JetBlocks For Elementor <= 1.5.2
Timeline
- 2026-09-13: disclosed
- 2026-09-17: advisory
- 2026-09-17: patched: Version 1.5.2.1 and later