CVE-2026-18405: stored cross-site scripting in jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Unauthenticated attackers can inject persistent JavaScript into pages served by the Jeg Kit for Elementor plugin, enabling stored cross-site scripting. CVE-2026-18405 affects Jeg Kit for Elementor versions 3.x — 3.2.16 and earlier — and results from insufficient input sanitization and output escaping of comment content. Successful exploitation requires that the targeted post renders a Jeg Kit Countdown widget so the plugin's frontend script initializes and executes forged widget markup placed in a comment; network access to the site and the ability to submit comments are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00292
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High urgency: this is an unauthenticated stored XSS in an internet-facing WordPress plugin and there is no fixed release listed for versions up to 3.2.16, so apply mitigations immediately.

What is CVE-2026-18405?

Unauthenticated attackers can inject persistent JavaScript into pages served by the Jeg Kit for Elementor plugin, enabling stored cross-site scripting. CVE-2026-18405 affects Jeg Kit for Elementor versions 3.x — 3.2.16 and earlier — and results from insufficient input sanitization and output escaping of comment content. Successful exploitation requires that the targeted post renders a Jeg Kit Countdown widget so the plugin's frontend script initializes and executes forged widget markup placed in a comment; network access to the site and the ability to submit comments are required. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress are affected?

BRANCHAFFECTEDFIXED
3.x3.2.16 and earlier

Is CVE-2026-18405 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-18405

  1. Remove or deactivate the Jeg Kit for Elementor plugin until a vendor fix is released.
  2. Disable or avoid using the Countdown widget on public posts to prevent its frontend script from initializing.
  3. Harden comment handling: require moderation, restrict who can post comments, and strip HTML from comments.
  4. Monitor web server and application logs for suspicious requests and injected scripts and follow vendor guidance when published.

Frequently asked questions

Is CVE-2026-18405 being actively exploited?

There are no public reports of exploitation of CVE-2026-18405 as of 2026-09-30.

Which Jeg Kit for Elementor versions are affected by CVE-2026-18405?

Jeg Kit for Elementor versions in the 3.x branch through 3.2.16 are affected; the advisory lists 3.2.16 and earlier as vulnerable.

Is there a patch for CVE-2026-18405?

No fixed version is listed for this vulnerability; the affected metadata shows no fixed release for 3.x/3.2.16 and earlier.

Does CVE-2026-18405 require authentication?

No, exploitation does not require authentication — an unauthenticated attacker can post a comment, but successful execution also requires the targeted post to render the plugin's Countdown widget.

References