CVE-2025-39448: WordPress JetElements For Elementor plugin <= 2.7.4.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.7.4.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.4.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39448?
The severity of CVE-2025-39448 is considered high due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-39448?
To fix CVE-2025-39448, update the JetElements For Elementor plugin to the latest version beyond 2.7.4.1.
What systems are affected by CVE-2025-39448?
CVE-2025-39448 affects JetElements For Elementor versions up to 2.7.4.1.
What kind of vulnerability is CVE-2025-39448?
CVE-2025-39448 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
What is the impact of CVE-2025-39448?
The impact of CVE-2025-39448 includes potential data theft, user session hijacking, and defacement of web pages.