Stored XSS in Jeg Elementor Kit WordPress Plugin via Video and Countdown Widgets
The Jeg Elementor Kit plugin for WordPress has a Stored Cross-Site Scripting vulnerability in its Video Button and Countdown Widgets through version 2.6.12. The issue stems from weak input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor-level access or higher can inject malicious web scripts into pages, which will then execute when other users view those pages.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jegtheme jeg elementor kit |