Junglewise Threat Intelligence

CVE-2026-66579: JetElements for Elementor Contributor XSS

CVE-2026-66579 · Severity: medium · CVSS 6.5 · Published 2026-09-17

Vendors: Crocoblock.

Executive brief

JetElements for Elementor is a popular WordPress plugin that extends the Elementor page builder with additional widgets and features. The plugin is vulnerable to cross-site scripting (XSS) attacks that allow a contributor-level user to inject malicious scripts, which could be executed when an administrator or other users interact with the affected content, potentially leading to account compromise or data theft.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in JetElements for Elementor versions up to 2.9.2.1 due to insufficient input sanitization and output encoding. The vulnerability allows a user with Contributor-level privileges to inject malicious JavaScript code that persists in the database and executes in the browsers of administrators or other users who view the affected content. Exploitation requires a privileged user (contributor) to create or edit content with embedded malicious payloads, but execution occurs when higher-privilege users access that content. The vulnerability was patched in version 2.9.2.2. Users should upgrade immediately to mitigate the risk of session hijacking, credential theft, or malware distribution.

Affected products

  • Crocoblock JetElements for Elementor <= 2.9.2.1

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Patched in version 2.9.2.2

References

Related threats