Stored Cross-Site Scripting Vulnerability in Jeg Elementor Kit Plugin by WordPress
CVE-2025-2944
6.4MEDIUM
What is CVE-2025-2944?
The Jeg Elementor Kit plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) that arises from inadequate input sanitization and output escaping on user-provided attributes within its Video Button and Countdown Widgets. This vulnerability enables attackers with contributor-level access or higher to embed arbitrary web scripts into pages, which will execute when a user visits the affected pages. Users are strongly encouraged to review their installations and apply the necessary updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Jeg Elementor Kit * <= 2.6.12
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D.Sim