Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #10
WordPress plugin Jeg Kit vulnerable to stored XSS flaw
Original: Jeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant Jav
Jeg Kit for Elementor, a WordPress add-on installed on more than 300,000 sites, contains an unauthenticated stored cross-site scripting vulnerability, tracked as CVE-2026-100180. An attacker can inject JavaScript through a blog comment, which then runs in visitors' browsers. All versions up to 3.2.19 are affected, and site owners are urged to update to version 3.2.20 immediately.
Why now: Security researchers are warning WordPress site owners to patch quickly because the flaw can be exploited by anyone without login on widely used sites.
Jeg Kit for ElementorWordPressElementor
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/814320