Input validation vulnerability in JetElements 2.7.2.1

The JetElements plugin for WordPress has a security issue called Stored Cross-Site Scripting. This happens when certain features, called widgets, are used. This vulnerability exists in all versions up to 2.7.2.1. The problem is caused by not properly checking the information entered by users and not properly protecting the output of that information. This means that someone with contributor-level access or higher can add harmful code to a webpage, which will then run whenever someone visits that page.

Detected in:

JetElements fixed vulnerable versions: >= * <= 2.7.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.