Sceawere

Vulnerability Detail

CVE-2026-105879UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in JetElements Plugin

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
16h ago
Vendor
Crocoblock
Product
JetElements For Elementor
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-06T09:17:41.620Z",
  "pubdate": "2026-10-06T09:17:41.620Z",
  "executiveSummary": "The Crocoblock JetElements For Elementor plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper neutralization of user-supplied input during the generation of web pages, allowing an attacker to inject and store malicious scripts within the application database.\nThe vulnerability affects all versions of JetElements For Elementor from n/a through 2.9.2.2. Successful exploitation permits the execution of unauthorized JavaScript in the context of a victim's browser session. By leveraging this vulnerability, an attacker can hijack user sessions, perform unauthorized actions on behalf of authenticated administrators, or exfiltrate sensitive data.\nThe risk implication is significant for WordPress environments utilizing this plugin, as it does not require complex infrastructure to exploit, provided the attacker has the necessary privileges to inject content. The exploit remains persistent, meaning the malicious payload will execute whenever a user views the affected page or administrative dashboard interface.",
  "technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw, categorized under CWE-79: Improper Neutralization of Input During Web Page Generation. The root cause lies in the application's failure to adequately sanitize or escape user-controlled input before rendering it within the Document Object Model (DOM) of generated web pages. Within the JetElements plugin, specific input fields—likely associated with plugin widgets or settings—do not implement sufficient output encoding or server-side input validation.\nAttack flow begins with an authenticated attacker, such as a contributor or an editor, who inputs malicious JavaScript into a vulnerable field provided by a JetElements widget. When this input is saved, the application writes the unsanitized payload directly into the database. Because the plugin does not properly neutralize this data during the retrieval and rendering process, the malicious script is embedded directly into the HTML response delivered to any user who visits the corresponding page.\nWhen a victim, potentially an administrator with higher privileges, accesses the compromised page, the browser interprets the stored string as an executable script rather than plain text. The payload executes within the victim's security context, granting the attacker access to session cookies, sensitive tokens, and the ability to perform administrative actions. This persists until the malicious content is manually removed from the database.\nThe technical impact is severe due to the potential for privilege escalation and cross-site request forgery (CSRF) via the XSS vector. The scope of exploitation is bounded by the visibility of the vulnerable component to the target user. As the plugin lacks a mechanism to verify the integrity of the injected content, the browser's Same-Origin Policy (SOP) is bypassed, allowing the injected script to access the DOM, read sensitive information from the page, or transmit data to a remote attacker-controlled server. Versions from n/a through 2.9.2.2 are inherently flawed in how they handle these data input cycles, requiring diligent oversight or code-level remediation to sanitize output contexts."
}
CVE-2026-105879: Stored XSS in JetElements Plugin (MEDIUM Severity, CVSS: 6.5) | Sceawere