medium · CVSS v3 5.4
CVE-2026-100180
The Jeg Kit for Elementor plugin for WordPress is vulnerable to stored XSS via comments in all versions up to 3.2.19. Unauthenticated attack
Overview
The Jeg Kit for Elementor plugin for WordPress is vulnerable to stored XSS via comments in all versions up to 3.2.19. Unauthenticated attackers can inject scripts that execute for any user viewing the page, potentially compromising user sessions or defacing content. The flaw bypasses moderation and sanitization, allowing immediate persistence.
Description
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Immediate persistence without moderator approval is possible when the attacker submits from an email address with at least one previously approved comment, though the widened allowlist bypasses sanitization regardless of approval status.
Impact
Confidentiality: attackers can steal user data or session cookies. Integrity: malicious scripts can alter page content or deface sites. Availability: not directly impacted. Defenders: site administrators and developers must patch or mitigate.
Remediation
Update Jeg Kit for Elementor to the latest version (≥3.2.20) or apply the vendor patch. If update not possible, disable comment functionality or enforce strict input sanitization via a WAF. Additionally, review comment moderation settings to ensure only approved content is displayed.
Risk context
Severity medium (CVSS 5.4). No EPSS data available. The vulnerability allows unauthenticated exploitation, so it should be addressed promptly but is not critical.
Affected products
- Jeg Kit for Elementor
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 5.4
- CVSS v4
- —
- EPSS
- —