Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

JetElements For Elementor — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in JetElements For Elementor, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with the JetElements plugin for Elementor, developed by CrocoBlock. It focuses on vulnerability aggregation to provide a centralized view of potential risks affecting users of this specific WordPress extension. The content collected here spans various vulnerability classes, including cross-site scripting, authorization bypasses, and file inclusion issues, covering reported incidents from early 2021 through late 2023. This timeframe captures the evolution of security postures as the plugin matured and updates were frequently deployed to address emerging threats. Visitors can utilize this resource to track vendor advisories from CrocoBlock and monitor how quickly patches are issued for critical flaws. By reviewing the aggregated data, developers and site administrators can understand the historical pattern of weakness classes that have impacted JetElements, allowing for better risk assessment during audits. Furthermore, users can look up the product’s specific vulnerability history to determine if their current version is susceptible to previously disclosed exploits. This structured approach helps distinguish between resolved issues and lingering concerns, offering a clear roadmap for security maintenance. The information serves as a technical reference rather than a promotional overview, aiming to support informed decision-making regarding plugin updates and configuration hardening. Understanding the context of each reported issue helps stakeholders prioritize remediation efforts based on the severity and exposure level of the affected components within the Elementor ecosystem.

Vendor: Crocoblock

CVE ID Title CVSS Severity Published
CVE-2026-65465 WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-07-23
CVE-2026-24958 WordPress JetElements For Elementor plugin <= 2.7.12.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-02-03
CVE-2025-64355 WordPress JetElements For Elementor plugin <= 2.7.12 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-12-18
CVE-2025-49939 WordPress JetElements For Elementor plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-10-22
CVE-2025-53983 WordPress JetElements For Elementor <= 2.7.7 - Sensitive Data Exposure Vulnerability CWE-201 6.5 Medium 2025-08-20
CVE-2025-55714 WordPress JetElements For Elementor Plugin <= 2.7.9 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium 2025-08-14
CVE-2025-53982 WordPress JetElements For Elementor plugin <= 2.7.7 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium 2025-07-16
CVE-2025-39447 WordPress JetElements For Elementor plugin <= 2.7.4.1 - Broken Access Control Vulnerability CWE-862 7.5 High 2025-05-19
CVE-2025-39448 WordPress JetElements For Elementor plugin <= 2.7.4.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-05-19
CVE-2023-48759 WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability CWE-862 7.5 High 2024-06-19
CVE-2023-48760 WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability CWE-862 8.2 High 2024-06-19
CVE-2023-48761 WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability CWE-862 6.3 Medium 2024-06-19
CVE-2023-39157 WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE) CWE-94 9.0 Critical 2023-12-31
CVE-2023-48762 WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 6.3 Medium 2023-12-18

All 14 known CVE vulnerabilities affecting JetElements For Elementor with full Chinese analysis, references, and POCs where available.