Sceawere
Vulnerability Detail
CVE-2026-62049UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in JetBlocks Elementor
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Crocoblock
- Product
- JetBlocks For Elementor
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through 1.5.2.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-09T10:16:38.067Z",
"pubdate": "2026-10-09T10:16:38.067Z",
"executiveSummary": "The Crocoblock JetBlocks For Elementor plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output neutralization.\nThis vulnerability allows an attacker to inject and persist malicious JavaScript payloads within the application's database. When an unsuspecting user, such as an administrator, views the compromised page or component, the payload executes within the context of their session.\nThe vulnerability affects versions n/a through 1.5.2.1 of the JetBlocks For Elementor plugin.\nThe impact of this flaw is significant, potentially leading to unauthorized actions performed on behalf of the victim, session hijacking, credential theft, or the defacement of the website.\nSuccessful exploitation requires the attacker to possess the capability to input data into the vulnerable fields or widgets provided by the plugin, which may require specific user privileges depending on the target site configuration.\nGiven the nature of Stored XSS, this vulnerability poses a severe risk as it does not require direct interaction from the victim beyond simply viewing the page where the malicious content is rendered.",
"technicalDetails": "The root cause of this vulnerability is the failure of the JetBlocks For Elementor plugin to adequately sanitize user-supplied input before storing it in the database and subsequent improper output neutralization when rendering that data in the frontend.\nThe plugin processes data for various elements or widgets without applying robust escaping functions (e.g., esc_html(), esc_js(), or wp_kses()) on dynamic content fields. This allows an attacker to bypass security filters and inject arbitrary HTML or JavaScript code into fields that are rendered globally or in administrative panels.\nThe attack flow typically initiates when an authenticated user (or an attacker with sufficient permissions to modify element settings) inputs a crafted malicious payload into a vulnerable field provided by the JetBlocks widget. The application accepts this input and persists it directly into the WordPress database without validation.\nWhen a legitimate user—often an administrator with higher privileges—loads the affected page, the JetBlocks plugin retrieves the malicious payload from the database and renders it into the Document Object Model (DOM) of the browser without adequate context-aware encoding. This causes the browser to treat the stored payload as executable script rather than plain text.\nUpon execution, the payload operates within the origin of the web application, granting the attacker access to the victim's session cookies, local storage, and the ability to perform actions within the WordPress dashboard as the logged-in user. This may include creating new administrative accounts, modifying site configurations, or injecting additional malicious scripts (such as backdoors or redirects) into other parts of the site.\nThe vulnerability is limited to versions n/a through 1.5.2.1. It is accessible via the network to any user authorized to manage the affected widgets, and its impact is amplified by the fact that the stored payload remains persistent, creating a long-term risk until the data is manually purged from the database or the underlying vulnerability is patched."
}