6.4
CVSSv3

CVE-2025-2944

CVSSv4: NA | CVSSv3: 6.4 | CVSSv2: NA | VMScore: 740 | EPSS: 0.00032 | KEV: Not Included
Published: 10/05/2025 Updated: 12/05/2025

Vulnerability Summary

Stored XSS in Jeg Elementor Kit WordPress Plugin via Video and Countdown Widgets

The Jeg Elementor Kit plugin for WordPress has a Stored Cross-Site Scripting vulnerability in its Video Button and Countdown Widgets through version 2.6.12. The issue stems from weak input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor-level access or higher can inject malicious web scripts into pages, which will then execute when other users view those pages.

Vulnerable Product Search on Vulmon Subscribe to Product

jegtheme jeg elementor kit