WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-14275 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 3.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14275 Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 3.0.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.0.2 3.0.2 2026-01-07

CVE-2025-14275

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.1 due to insufficient input sanitization in the countdown widget's redirect functionality. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary JavaScript that will execute when an administrator or other user views the page containing the malicious countdown element.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.