CVE-2025-9978: Jeg Elementor Kit < 2.7.0 - Author+ Stored XSS
The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9978?
CVE-2025-9978 has been classified as a cross site scripting vulnerability, which can potentially allow attackers to execute arbitrary scripts in the context of the affected website.
How do I fix CVE-2025-9978?
To mitigate CVE-2025-9978, update the Jeg Kit for Elementor plugin to version 2.7.0 or later where the issue has been resolved.
What software is affected by CVE-2025-9978?
CVE-2025-9978 affects the Jeg Kit for Elementor WordPress plugin versions prior to 2.7.0.
What is the impact of CVE-2025-9978?
The impact of CVE-2025-9978 includes potential unauthorized access and manipulation of website content through executed scripts.
How does CVE-2025-9978 allow for cross site scripting?
CVE-2025-9978 allows for cross site scripting due to the lack of sanitization for SVG file contents when uploaded via xmlrpc.php.