Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.3 WordPress CVE-2026-105879

Stored XSS Vulnerability in JetElements For Elementor (CVE-2026-105879)

A stored cross-site scripting (XSS) vulnerability affects JetElements For Elementor versions up to 2.9.2.2. The vendor has not yet confirmed a fixed version.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A stored cross-site scripting (XSS) vulnerability has been identified in JetElements For Elementor, a WordPress plugin developed by Crocoblock. The issue is tracked as CVE-2026-105879 and affects versions through 2.9.2.2. As of this writing, no confirmed fixed version has been published by the vendor.

What Happened

A vulnerability classified as Improper Neutralization of Input During Web Page Generation (CWE-79), commonly known as stored Cross-Site Scripting (XSS), was disclosed for the JetElements For Elementor plugin. Stored XSS vulnerabilities allow malicious script content to be saved by the application and later executed in the browser of users who view the affected content.

Technical Cause

The vulnerability stems from improper neutralization of user-supplied input during web page generation, allowing injected script content to be stored and later rendered as active content when the affected page is viewed. This is categorized under CWE-79 (Cross-Site Scripting).

Why It Matters

The vulnerability has a CVSS base score of 6.5, reflecting a network-exploitable issue that requires low attacker privileges and user interaction, with a scope change and limited impact to confidentiality, integrity, and availability. Because the flaw is stored (persistent), malicious content could remain active on a site and affect multiple visitors or administrators who interact with the compromised content until it is removed or the plugin is patched.

Who Is Affected

Websites using the JetElements For Elementor plugin (developed by Crocoblock) in versions up to and including 2.9.2.2 are affected. This plugin is reported to be used on a substantial number of WordPress sites, increasing the potential scope of exposure.

Affected Versions

JetElements For Elementor versions through 2.9.2.2 are affected. A version identified as 2.9.2.3 appears in the plugin's version-tracking data as a boundary reference, but the fact package does not confirm that this version resolves the vulnerability. Site owners should verify directly with the vendor before assuming a fix is available.

Fixes and Mitigation

No confirmed fix has been verified at this time. The fact package does not provide evidence that a patched release has been officially confirmed as resolving this vulnerability. Site owners should monitor the vendor's official channels for an update addressing CVE-2026-105879.

Recommended Action

Site administrators using JetElements For Elementor should check for plugin updates regularly, review the vendor's official changelog for a fix addressing this issue, and consider limiting access to content-editing capabilities to trusted users while a fix is pending. Monitoring stored content for unexpected script injections is also advisable as a precaution.

PatchBriefing score

4.3 / 10 · Medium

Official CVSS: 6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Why this score

This vulnerability received a PatchBriefing score of 4.3, driven primarily by its CVSS base score of 6.5. The score reflects that exploitation requires some attacker privilege and user interaction (not a fully unauthenticated, no-interaction attack), which limits the contribution to the overall risk rating. Additional factors include the lack of a confirmed fix and the plugin's substantial install base, both of which modestly raise the score. There is no evidence of known exploitation or public exploit code at this time.

Affected versions

JetElements (Crocoblock) < 2.9.2.3
vulnerable

Reported fixes

No confirmed fix has been verified at this time. The fact package does not provide evidence that a patched release has been officially confirmed as resolving this vulnerability. Site owners should monitor the vendor's official channels for an update addressing CVE-2026-105879.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
Unified report
Stored XSS Vulnerability in JetElements For Elementor (CVE-2026-105879)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email