CVE-2026-11380: JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animationeffect setting before it is rendered inside an HTML class attribute. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/jetwidgets-for-elementorto a version that resolves this vulnerability.Fixed in 1.0.21 - Compensating control
Limit access to the WordPress Elementor/JetWidgets editing capabilities so only trusted administrators can create or edit pages that use the Animated Box widget (authenticated author-level access and above can inject scripts).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11380?
The severity of CVE-2026-11380 is rated as medium with a score of 6.4.
What is CVE-2026-11380?
CVE-2026-11380 is a vulnerability in JetWidgets For Elementor that allows for stored cross-site scripting through the Animated Box 'animation_effect' setting.
How do I fix CVE-2026-11380?
To fix CVE-2026-11380, update the JetWidgets For Elementor plugin to version 1.0.22 or later.
What types of attacks can CVE-2026-11380 facilitate?
CVE-2026-11380 can facilitate stored cross-site scripting attacks on affected WordPress sites.
What versions of JetWidgets For Elementor are affected by CVE-2026-11380?
CVE-2026-11380 affects JetWidgets For Elementor versions up to and including 1.0.21.