Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Dec 12, 2025

JetWidgets For Elementor Vulnerabilities

Review known vulnerability records for the WordPress plugin JetWidgets For Elementor (`jetwidgets-for-elementor`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-8195, CVE-2024-10323 and CVE-2024-4626, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
0
Patch Coverage
100%
Last Updated
Dec 13, 2025
Priority CVE Quick Links

Fast paths into JetWidgets For Elementor CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
CVE-2025-8195 Medium 1.0.21
CVE-2025-8195 JetWidgets For Elementor Stored Cross-Site Scripting

JetWidgets For Elementor <= 1.0.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets

CVE-2024-10323 Medium 1.0.19
CVE-2024-10323 JetWidgets For Elementor File Upload

JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

CVE-2024-4626 Medium 1.0.18
CVE-2024-4626 JetWidgets For Elementor Stored Cross-Site Scripting

JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters

CVE-2024-2507 Medium 1.0.17
CVE-2024-2507 JetWidgets For Elementor Stored Cross-Site Scripting

JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL

CVE-2024-2138 Medium 1.0.16
CVE-2024-2138 JetWidgets For Elementor Stored Cross-Site Scripting

JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget

CVE-2023-0034 Medium 1.0.14
CVE-2023-0034 JetWidgets For Elementor Stored Cross-Site Scripting

JetWidgets For Elementor <= 1.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2021-24268 Medium 1.0.9
CVE-2021-24268 JetWidgets For Elementor Stored Cross-Site Scripting

JetWidgets For Elementor <= 1.0.8 - Contributor+ Stored Cross-Site Scripting

CVE-2023-0086 Medium 1.0.13
CVE-2023-0086 JetWidgets For Elementor Cross-Site Scripting

JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for JetWidgets For Elementor so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2025-8195, CVE-2024-10323 and CVE-2024-4626
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for JetWidgets For Elementor

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-8195
CVE-2025-8195: JetWidgets For Elementor <= 1.0.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison and Subscribe widgets in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attribut...

Published
Dec 12, 2025
Patched Release
1.0.21
Affected Versions
Versions up to 1.0.20
Next Step
Update to 1.0.21 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10323
CVE-2024-10323: JetWidgets For Elementor <= 1.0.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Published
Nov 11, 2024
Patched Release
1.0.19
Affected Versions
Versions up to 1.0.18
Next Step
Update to 1.0.19 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4626
CVE-2024-4626: JetWidgets For Elementor <= 1.0.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...

Published
Jun 19, 2024
Patched Release
1.0.18
Affected Versions
Versions up to 1.0.17
Next Step
Update to 1.0.18 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2507
CVE-2024-2507: JetWidgets For Elementor <= 1.0.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Published
Mar 20, 2024
Patched Release
1.0.17
Affected Versions
Versions up to 1.0.16
Next Step
Update to 1.0.17 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2138
CVE-2024-2138: JetWidgets For Elementor <= 1.0.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Published
Mar 13, 2024
Patched Release
1.0.16
Affected Versions
Versions up to 1.0.15
Next Step
Update to 1.0.16 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-0034
CVE-2023-0034: JetWidgets For Elementor <= 1.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

Published
Jan 19, 2023
Patched Release
1.0.14
Affected Versions
Versions up to 1.0.13
Next Step
Update to 1.0.14 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-0086
CVE-2023-0086: JetWidgets for Elementor <= 1.0.12 - Cross-Site Request Forgery to Settings Update

The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.12. This is due to missing nonce validation on the save() function. This makes it possible for unauthenticated attackers to to modify the plugin's s...

Published
Jan 04, 2023
Patched Release
1.0.13
Affected Versions
Versions up to 1.0.12
Next Step
Update to 1.0.13 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24268
CVE-2021-24268: JetWidgets For Elementor <= 1.0.8 - Contributor+ Stored Cross-Site Scripting

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Published
Apr 13, 2021
Patched Release
1.0.9
Affected Versions
Versions before 1.0.9
Next Step
Update to 1.0.9 or newer if supported.