CVE Database /
CVE-2026-24958
CVE · Medium
CVE-2026-24958 — JetElements For Elementor [jet-elements] < 2.7.12.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-24958
|
JetElements For Elementor [jet-elements] < 2.7.12.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.5
|
< 2.7.12.3
|
2.7.12.3 |
2025-12-30 |
—
|
CVE-2026-24958
The JetElements For Elementor plugin for WordPress is susceptible to a type of attack where malicious code can be embedded into the site's content, allowing authorized users with elevated permissions to introduce executable scripts that run when other users visit affected pages. This vulnerability arises from inadequate measures to cleanse and encode user input before displaying it on the website. Affected versions include all up to 2.7.12.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings