<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:jegtheme:jeg_kit_for_elementor:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ajegthemejeg_kit_for_elementorwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 12:05:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ajegthemejeg_kit_for_elementorwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in Jeg Kit for Elementor</title><link>https://feed.craftedsignal.io/briefs/2026-09-jeg-kit-xss/</link><pubDate>Fri, 18 Sep 2026 12:05:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-jeg-kit-xss/</guid><description>The Jeg Kit for Elementor plugin for WordPress contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary scripts when a specific widget is rendered.</description><content:encoded><![CDATA[<p>The Jeg Kit for Elementor (Powerful Addons for Elementor, Widgets &amp; Templates) plugin for WordPress contains a critical security flaw identified as CVE-2026-18405. The vulnerability resides in the insufficient sanitization and output escaping of user-supplied data within comment fields. All versions of the plugin up to and including 3.2.16 are affected. An unauthenticated attacker can exploit this flaw by injecting malicious JavaScript into a post's comments section. The payload remains dormant until a user views a page on the site that utilizes the Jeg Kit Countdown widget. Once the widget initializes, it forces the execution of the injected script within the context of the victim's browser, potentially allowing attackers to hijack sessions or perform unauthorized actions on behalf of the user.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-18405 leads to stored XSS, allowing unauthenticated attackers to execute arbitrary web scripts in the browser of any user viewing a page containing the Jeg Kit Countdown widget. This poses a significant risk for administrative account takeover, data theft, and unauthorized site manipulation. The vulnerability affects all WordPress instances running Jeg Kit for Elementor version 3.2.16 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update the Jeg Kit for Elementor plugin to the latest available version provided by Jegtheme to address the input sanitization flaw in CVE-2026-18405.</li>
<li>Audit comments sections on WordPress sites utilizing the Jeg Kit Countdown widget for suspicious markup or script tags.</li>
<li>Implement a strict Content Security Policy (CSP) to mitigate the impact of potential XSS vulnerabilities by restricting the sources from which scripts can be executed.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>web-application</category></item></channel></rss>