CVE-2026-62049: WordPress JetBlocks For Elementor plugin <= 1.5.2.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through 1.5.2.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetBlocks For Elementorto a version that resolves this vulnerability.Fixed in 1.5.2.2
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The vector is network-accessible, but exploitation requires low-level privileges and user interaction. An attacker would need an account with the required low privileges to submit malicious content, and a victim would need to view or otherwise interact with the injected content.
What versions are affected?
JetBlocks For Elementor versions through 1.5.2.1 are affected. The available data does not identify a fixed version.
What is the potential impact?
This is a stored XSS issue. Successful exploitation can affect confidentiality, integrity, and availability at low impact, and the scope may extend beyond the vulnerable component.