CVE · Medium

CVE-2026-24958 — JetElements For Elementor [jet-elements] < 2.7.12.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-24958 JetElements For Elementor [jet-elements] < 2.7.12.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.7.12.3 2.7.12.3 2025-12-30

CVE-2026-24958

The JetElements For Elementor plugin for WordPress is susceptible to a type of attack where malicious code can be embedded into the site's content, allowing authorized users with elevated permissions to introduce executable scripts that run when other users visit affected pages. This vulnerability arises from inadequate measures to cleanse and encode user input before displaying it on the website. Affected versions include all up to 2.7.12.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.