WordPress Plugin Vulnerabilities

Jeg Elementor Kit < 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Description

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.1 due to insufficient input sanitization in the countdown widget's redirect functionality. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary JavaScript that will execute when an administrator or other user views the page containing the malicious countdown element.

Affects Plugins

Fixed in 3.0.2

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Webbernaut
Verified
No

Timeline

Publicly Published
2026-01-07 (about 4 months ago)
Added
2026-01-07 (about 4 months ago)
Last Updated
2026-01-08 (about 4 months ago)

Other