{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/jeg-kit-for-elementor--3.2.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jegtheme:jeg_kit_for_elementor:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18405"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Jeg Kit for Elementor (\u003c= 3.2.16)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-application"],"_cs_type":"advisory","_cs_vendors":["Jegtheme"],"content_html":"\u003cp\u003eThe Jeg Kit for Elementor (Powerful Addons for Elementor, Widgets \u0026amp; Templates) plugin for WordPress contains a critical security flaw identified as CVE-2026-18405. The vulnerability resides in the insufficient sanitization and output escaping of user-supplied data within comment fields. All versions of the plugin up to and including 3.2.16 are affected. An unauthenticated attacker can exploit this flaw by injecting malicious JavaScript into a post's comments section. The payload remains dormant until a user views a page on the site that utilizes the Jeg Kit Countdown widget. Once the widget initializes, it forces the execution of the injected script within the context of the victim's browser, potentially allowing attackers to hijack sessions or perform unauthorized actions on behalf of the user.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18405 leads to stored XSS, allowing unauthenticated attackers to execute arbitrary web scripts in the browser of any user viewing a page containing the Jeg Kit Countdown widget. This poses a significant risk for administrative account takeover, data theft, and unauthorized site manipulation. The vulnerability affects all WordPress instances running Jeg Kit for Elementor version 3.2.16 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the Jeg Kit for Elementor plugin to the latest available version provided by Jegtheme to address the input sanitization flaw in CVE-2026-18405.\u003c/li\u003e\n\u003cli\u003eAudit comments sections on WordPress sites utilizing the Jeg Kit Countdown widget for suspicious markup or script tags.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content Security Policy (CSP) to mitigate the impact of potential XSS vulnerabilities by restricting the sources from which scripts can be executed.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T12:05:08Z","date_published":"2026-09-18T12:05:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jeg-kit-xss/","summary":"The Jeg Kit for Elementor plugin for WordPress contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary scripts when a specific widget is rendered.","title":"Stored XSS Vulnerability in Jeg Kit for Elementor","url":"https://feed.craftedsignal.io/briefs/2026-09-jeg-kit-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Jeg Kit for Elementor (\u003c= 3.2.16)","version":"https://jsonfeed.org/version/1.1"}