CVE-2023-39157: WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39157?
CVE-2023-39157 has a medium severity rating due to its potential for code injection and remote code execution.
How does CVE-2023-39157 affect users of JetElements For Elementor?
CVE-2023-39157 can allow authenticated attackers to inject malicious code, leading to unauthorized control over the affected WordPress site.
How do I fix CVE-2023-39157?
To fix CVE-2023-39157, update JetElements For Elementor to the latest version beyond 2.6.10, where the vulnerability is patched.
Is CVE-2023-39157 a known issue for specific versions of JetElements?
Yes, CVE-2023-39157 affects JetElements For Elementor versions up to and including 2.6.10.
What kind of vulnerability is CVE-2023-39157 classified as?
CVE-2023-39157 is classified as an Improper Control of Generation of Code vulnerability, commonly referred to as code injection.