First published: Mon Mar 31 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetBlocks For Elementor allows Stored XSS. This issue affects JetBlocks For Elementor: from n/a through 1.3.16.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound JetBlocks For Elementor | <=1.3.16 | |
NotFound JetBlocks For Elementor | <=1.3.16 |
Update the WordPress JetBlocks For Elementor plugin to the latest available version (at least 1.3.16.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30987 is classified as a high-severity Cross-site Scripting (XSS) vulnerability.
To fix CVE-2025-30987, update NotFound JetBlocks For Elementor to a version later than 1.3.16.
The impacts of CVE-2025-30987 can include unauthorized access to user data and the ability to execute malicious scripts in the context of the user's browser.
CVE-2025-30987 affects all versions of JetBlocks For Elementor from n/a up to and including 1.3.16.
Yes, JetBlocks For Elementor is maintained by NotFound.