Stored Cross-Site Scripting Vulnerability in Jeg Kit for Elementor Plugin by WordPress
CVE-2026-100180

5.4MEDIUM

What is CVE-2026-100180?

The Jeg Kit for Elementor plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary JavaScript through comments. When executed, these scripts will run whenever a user accesses the affected page, leading to potential exploitation. An attacker can achieve immediate persistence if they submit a comment from an email address associated with a previously approved comment, thus bypassing the sanitization mechanisms in place.

Affected Version(s)

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress 0 <= 3.2.19

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dthangws
.