CVE-2025-55714: WordPress JetElements For Elementor Plugin <= 2.7.9 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor allows Stored XSS. This issue affects JetElements For Elementor: from n/a through 2.7.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.9.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55714?
CVE-2025-55714 is classified as a high-severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-55714?
To fix CVE-2025-55714, update the Crocoblock JetElements For Elementor plugin to version 2.8.0 or later.
Who is affected by CVE-2025-55714?
CVE-2025-55714 affects users of Crocoblock JetElements For Elementor versions up to and including 2.7.9.
What type of vulnerability is CVE-2025-55714?
CVE-2025-55714 is an improper neutralization of input during web page generation leading to a Stored Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-55714 be exploited remotely?
Yes, CVE-2025-55714 can be exploited remotely by an attacker to execute malicious scripts in the context of the affected web application.