Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

JetElements For Elementor — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in JetElements For Elementor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates public security vulnerabilities and weaknesses associated with JetElements For Elementor, a popular third-party plugin for the WordPress page builder framework. The collection focuses on identifying potential entry points, data exposure risks, and functionality bypasses that may affect installations relying on this specific vendor's codebase. The vulnerabilities listed here span from the initial public disclosure of known issues through to recent patches, covering a broad historical range to provide comprehensive context. This timeline includes critical severity flaws that allow remote code execution, as well as lower-severity configuration errors that could lead to information leakage or unauthorized access. By consolidating these records, the page aims to serve as a centralized reference for security researchers, system administrators, and developers who need to assess the risk posture of their environments. On this page, you can track a vendor's advisories to stay informed about how JetElements addresses specific flaws over time. You can also understand a weakness class by examining the underlying causes and common remediation strategies across different reports. Furthermore, looking up a product's vulnerability history allows stakeholders to evaluate the frequency and impact of security incidents, aiding in decision-making for updates, migrations, or continued usage. This resource does not offer mitigation advice but strictly catalogues disclosed issues for informational and auditing purposes.

Vendor: Crocoblock

CVE IDTitleCVSSSeverityPublished
CVE-2026-24958 WordPress JetElements For Elementor plugin <= 2.7.12.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-02-03
CVE-2025-64355 WordPress JetElements For Elementor plugin <= 2.7.12 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-12-18
CVE-2025-49939 WordPress JetElements For Elementor plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-10-22
CVE-2025-53983 WordPress JetElements For Elementor <= 2.7.7 - Sensitive Data Exposure Vulnerability CWE-201 6.5 Medium2025-08-20
CVE-2025-55714 WordPress JetElements For Elementor Plugin <= 2.7.9 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium2025-08-14
CVE-2025-53982 WordPress JetElements For Elementor plugin <= 2.7.7 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium2025-07-16
CVE-2025-39447 WordPress JetElements For Elementor plugin <= 2.7.4.1 - Broken Access Control Vulnerability CWE-862 7.5 High2025-05-19
CVE-2025-39448 WordPress JetElements For Elementor plugin <= 2.7.4.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-05-19
CVE-2023-48759 WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability CWE-862 7.5 High2024-06-19
CVE-2023-48760 WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Broken Access Control vulnerability CWE-862 8.2 High2024-06-19
CVE-2023-48761 WordPress JetElements For Elementor plugin <= 2.6.13 - Broken Access Control vulnerability CWE-862 6.3 Medium2024-06-19
CVE-2023-39157 WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE) CWE-94 9.0 Critical2023-12-31
CVE-2023-48762 WordPress JetElements For Elementor Plugin <= 2.6.13 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 6.3 Medium2023-12-18

All 13 known CVE vulnerabilities affecting JetElements For Elementor with full Chinese analysis, references, and POCs where available.