MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #10

WordPress plugin Jeg Kit vulnerable to stored XSS flaw

Original: Jeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant Jav

Jeg Kit for Elementor, a WordPress add-on installed on more than 300,000 sites, contains an unauthenticated stored cross-site scripting vulnerability, tracked as CVE-2026-100180. An attacker can inject JavaScript through a blog comment, which then runs in visitors' browsers. All versions up to 3.2.19 are affected, and site owners are urged to update to version 3.2.20 immediately.

Why now: Security researchers are warning WordPress site owners to patch quickly because the flaw can be exploited by anyone without login on widely used sites.

Jeg Kit for ElementorWordPressElementor

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/814320