Stored Cross-Site Scripting in Jeg Kit for Elementor Plugin
CVE-2026-6916
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 May 2026
What is CVE-2026-6916?
The Jeg Kit for Elementor plugin, a widely used tool for building and enhancing Elementor sites, is susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability arises from the insufficient sanitization of user input through the 'sg_content_number_prefix' parameter. Attackers with contributor-level access can exploit this flaw to inject malicious scripts into pages. These scripts will execute whenever users visit the compromised pages, potentially leading to data theft, session hijacking, or the spread of malware. To mitigate this risk, it is essential for users to update to the latest version of the plugin immediately.
Affected Version(s)
Jeg Kit for Elementor β Powerful Addons for Elementor, Widgets & Templates for WordPress 0 <= 3.1.0