CVE-2025-9978
MEDIUMJeg Kit for Elementor < 2.7.0 - Cross-Site Scripting via SVG File Upload
Title source: llmDescription
The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.
References (1)
Core 1
Core References
Third Party Advisory exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/cef78a77-c66d-4d62-8d49-140ca2d04d5b/
Scores
CVSS v3
6.8
EPSS
0.0027
EPSS Percentile
19.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (1)
Unknown/Jeg Kit for Elementor
< 2.7.0
Published
Oct 24, 2025
Tracked Since
Feb 18, 2026