CVE-2026-66576: WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2026
·Updated
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
Affected Software
1 affected component
WordPress JetBlocks For Elementor<=1.5.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetBlocks For Elementor pluginto a version that resolves this vulnerability.Fixed in 1.5.2.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack requires authenticated Contributor-level access. It also requires a user to interact with the attacker-controlled content.
2
What is the potential impact if the vulnerability is exploited?
Successful exploitation can affect confidentiality, integrity, and availability with low impact in each area. The scope is changed, meaning the vulnerable plugin may enable impacts beyond its own security authority.
3
Which plugin versions are affected?
JetBlocks For Elementor versions up to and including 1.5.2 are affected.