Stored Cross-Site Scripting Vulnerability in Jeg Elementor Kit Plugin by WordPress
CVE-2025-2944

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 May 2025

What is CVE-2025-2944?

The Jeg Elementor Kit plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) that arises from inadequate input sanitization and output escaping on user-provided attributes within its Video Button and Countdown Widgets. This vulnerability enables attackers with contributor-level access or higher to embed arbitrary web scripts into pages, which will execute when a user visits the affected pages. Users are strongly encouraged to review their installations and apply the necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Jeg Elementor Kit * <= 2.6.12

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.
CVE-2025-2944 : Stored Cross-Site Scripting Vulnerability in Jeg Elementor Kit Plugin by WordPress