Sceawere
Vulnerability Detail
CVE-2026-105879UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in JetElements Plugin
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 16h ago
- Vendor
- Crocoblock
- Product
- JetElements For Elementor
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T09:17:41.620Z",
"pubdate": "2026-10-06T09:17:41.620Z",
"executiveSummary": "The Crocoblock JetElements For Elementor plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper neutralization of user-supplied input during the generation of web pages, allowing an attacker to inject and store malicious scripts within the application database.\nThe vulnerability affects all versions of JetElements For Elementor from n/a through 2.9.2.2. Successful exploitation permits the execution of unauthorized JavaScript in the context of a victim's browser session. By leveraging this vulnerability, an attacker can hijack user sessions, perform unauthorized actions on behalf of authenticated administrators, or exfiltrate sensitive data.\nThe risk implication is significant for WordPress environments utilizing this plugin, as it does not require complex infrastructure to exploit, provided the attacker has the necessary privileges to inject content. The exploit remains persistent, meaning the malicious payload will execute whenever a user views the affected page or administrative dashboard interface.",
"technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw, categorized under CWE-79: Improper Neutralization of Input During Web Page Generation. The root cause lies in the application's failure to adequately sanitize or escape user-controlled input before rendering it within the Document Object Model (DOM) of generated web pages. Within the JetElements plugin, specific input fields—likely associated with plugin widgets or settings—do not implement sufficient output encoding or server-side input validation.\nAttack flow begins with an authenticated attacker, such as a contributor or an editor, who inputs malicious JavaScript into a vulnerable field provided by a JetElements widget. When this input is saved, the application writes the unsanitized payload directly into the database. Because the plugin does not properly neutralize this data during the retrieval and rendering process, the malicious script is embedded directly into the HTML response delivered to any user who visits the corresponding page.\nWhen a victim, potentially an administrator with higher privileges, accesses the compromised page, the browser interprets the stored string as an executable script rather than plain text. The payload executes within the victim's security context, granting the attacker access to session cookies, sensitive tokens, and the ability to perform administrative actions. This persists until the malicious content is manually removed from the database.\nThe technical impact is severe due to the potential for privilege escalation and cross-site request forgery (CSRF) via the XSS vector. The scope of exploitation is bounded by the visibility of the vulnerable component to the target user. As the plugin lacks a mechanism to verify the integrity of the injected content, the browser's Same-Origin Policy (SOP) is bypassed, allowing the injected script to access the DOM, read sensitive information from the page, or transmit data to a remote attacker-controlled server. Versions from n/a through 2.9.2.2 are inherently flawed in how they handle these data input cycles, requiring diligent oversight or code-level remediation to sanitize output contexts."
}