DIRAS TAKE
High urgency: this is an unauthenticated stored XSS in an internet-facing WordPress plugin and there is no fixed release listed for versions up to 3.2.16, so apply mitigations immediately.
What is CVE-2026-18405?
Unauthenticated attackers can inject persistent JavaScript into pages served by the Jeg Kit for Elementor plugin, enabling stored cross-site scripting. CVE-2026-18405 affects Jeg Kit for Elementor versions 3.x — 3.2.16 and earlier — and results from insufficient input sanitization and output escaping of comment content. Successful exploitation requires that the targeted post renders a Jeg Kit Countdown widget so the plugin's frontend script initializes and executes forged widget markup placed in a comment; network access to the site and the ability to submit comments are required. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.2.16 and earlier |
Is CVE-2026-18405 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-18405
- Remove or deactivate the Jeg Kit for Elementor plugin until a vendor fix is released.
- Disable or avoid using the Countdown widget on public posts to prevent its frontend script from initializing.
- Harden comment handling: require moderation, restrict who can post comments, and strip HTML from comments.
- Monitor web server and application logs for suspicious requests and injected scripts and follow vendor guidance when published.
Frequently asked questions
Is CVE-2026-18405 being actively exploited?
There are no public reports of exploitation of CVE-2026-18405 as of 2026-09-30.
Which Jeg Kit for Elementor versions are affected by CVE-2026-18405?
Jeg Kit for Elementor versions in the 3.x branch through 3.2.16 are affected; the advisory lists 3.2.16 and earlier as vulnerable.
Is there a patch for CVE-2026-18405?
No fixed version is listed for this vulnerability; the affected metadata shows no fixed release for 3.x/3.2.16 and earlier.
Does CVE-2026-18405 require authentication?
No, exploitation does not require authentication — an unauthenticated attacker can post a comment, but successful execution also requires the targeted post to render the plugin's Countdown widget.
References
- nvd.nist.gov/vuln/detail/CVE-2026-18405
- cve.org/CVERecord?id=CVE-2026-18405
- wordfence.com/threat-intel/vulnerabilities/id/2e4a9e9a-7bdc-4f51-ac3f-d6627b4f62c7?source=cve
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/assets/js/elements/countdown.js#L1
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/helper.php#L868
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/lib/jeg-framework/util/framework-helper.php#L153
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.10/class/elements/views/class-countdown-view.php#L107
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/assets/js/elements/countdown.js#L1
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/helper.php#L868
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/lib/jeg-framework/util/framework-helper.php#L153
- plugins.trac.wordpress.org/browser/jeg-elementor-kit/tags/3.2.7/class/elements/views/class-countdown-view.php#L107
- plugins.trac.wordpress.org/changeset?reponame=&new=3690125%40jeg-elementor-kit%2Ftags%2F3.2.17&old=3679095%40jeg-elementor-kit%2Ftags%2F3.2.16
- plugins.trac.wordpress.org/changeset/3690125/jeg-elementor-kit/trunk/class/elements/views/class-countdown-view.php
- All jegtheme CVEs on CVE Radar
- CVEs published in September 2026