Stored Cross-Site Scripting in Jeg Kit for Elementor Plugin
CVE-2026-6916

6.4MEDIUM

What is CVE-2026-6916?

The Jeg Kit for Elementor plugin, a widely used tool for building and enhancing Elementor sites, is susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability arises from the insufficient sanitization of user input through the 'sg_content_number_prefix' parameter. Attackers with contributor-level access can exploit this flaw to inject malicious scripts into pages. These scripts will execute whenever users visit the compromised pages, potentially leading to data theft, session hijacking, or the spread of malware. To mitigate this risk, it is essential for users to update to the latest version of the plugin immediately.

Affected Version(s)

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress 0 <= 3.1.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Justin Nam
.