CVE-2025-64355: WordPress JetElements For Elementor plugin <= 2.7.12 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through 2.7.12.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64355?
CVE-2025-64355 has been classified with a severity level that indicates it poses a significant risk due to the potential for DOM-Based XSS attacks.
How do I fix CVE-2025-64355?
To mitigate CVE-2025-64355, update Crocoblock JetElements For Elementor to version 2.7.13 or later.
What versions are affected by CVE-2025-64355?
CVE-2025-64355 affects Crocoblock JetElements For Elementor versions from n/a up to and including 2.7.12.
What type of vulnerability is CVE-2025-64355?
CVE-2025-64355 is an Improper Neutralization of Input During Web Page Generation vulnerability, leading to Cross-site Scripting (XSS).
Is CVE-2025-64355 a risk for WordPress sites?
Yes, CVE-2025-64355 can be a risk for WordPress sites using the JetElements For Elementor plugin version 2.7.12 or earlier.