CVE-2025-49939: WordPress JetElements For Elementor plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49939?
CVE-2025-49939 has a medium severity rating due to its ability to allow Stored XSS attacks.
How do I fix CVE-2025-49939?
To fix CVE-2025-49939, update the JetElements For Elementor plugin to version 2.7.9 or higher.
What are the consequences of CVE-2025-49939?
Exploitation of CVE-2025-49939 can lead to unauthorized access to user accounts and manipulation of the website.
Which versions of JetElements For Elementor are affected by CVE-2025-49939?
CVE-2025-49939 affects all versions of JetElements For Elementor from n/a through version 2.7.8.
Is CVE-2025-49939 specific to certain platforms?
CVE-2025-49939 is known to affect both CrocoBlock and WordPress implementations of the JetElements For Elementor plugin.