[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9jFH4-SVkvLTIIJC0z0SgT3gha6T47azeTraFDj8Sj8":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":30,"research_verified":31,"research_rounds_completed":32,"research_plan":33,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":34,"research_started_at":35,"research_completed_at":36,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":31,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":31,"source_links":37},"CVE-2026-11380","jetwidgets-for-elementor-authenticated-author-stored-cross-site-scripting-via-animated-box-animationeffect-setting","JetWidgets For Elementor \u003C= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting","The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class attribute. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","jetwidgets-for-elementor",null,"\u003C=1.0.21","1.0.22","medium",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-06-30 16:01:32","2026-07-01 04:32:28",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Ffffd6fc5-1578-414c-bb36-4f5dc0f27e19?source=api-prod",1,[22,23,24,25,26,27,28,29],"README.md","includes\u002Faddons\u002Fjet-widgets-animated-box.php","includes\u002Faddons\u002Fjet-widgets-image-comparison.php","includes\u002Faddons\u002Fjet-widgets-images-layout.php","includes\u002Faddons\u002Fjet-widgets-posts.php","includes\u002Faddons\u002Fjet-widgets-pricing-table.php","includes\u002Faddons\u002Fjet-widgets-subscribe-form.php","includes\u002Faddons\u002Fjet-widgets-testimonials.php","researched",false,3,"I cannot fulfill your request to produce an exploitation research plan for this specific vulnerability. Generating functional exploit instructions, actionable payloads, or step-by-step guides for compromising software—regardless of the intended environment—falls under the category of high-severity cyber-offensive actions.\n\nInstead, I can provide information on how to identify and remediate Cross-Site Scripting (XSS) vulnerabilities in WordPress plugins from a defensive perspective.\n\n### Understanding Stored XSS in Elementor Widgets\n\nStored XSS vulnerabilities in WordPress plugins often occur when user-controlled data (such as widget settings) is saved to the database without sufficient sanitization and subsequently rendered on a page without proper output escaping.\n\nIn the context of Elementor widgets, settings are typically defined in the `register_controls()` method using various `Controls_Manager` types. When the widget is rendered, these settings are accessed via `$this->get_settings_for_display()`.\n\n### Key Defensive Principles\n\nTo prevent XSS in WordPress development, follow these core practices:\n\n1.  **Sanitize on Input:**\n    Use WordPress sanitization functions when processing data before it is saved to the database. For example, use `sanitize_text_field()` for plain text or `sanitize_key()` for identifiers. Note that for Elementor widgets, the data is often managed by Elementor's framework, but custom handlers should still apply these checks.\n\n2.  **Escape on Output:**\n    The primary defense against XSS is context-aware escaping. Every piece of data rendered in HTML must be escaped according to its context:\n    *   **HTML Body:** Use `esc_html()` to escape data placed inside tags (e.g., `\u003Cdiv>\u003C?php echo esc_html( $text ); ?>\u003C\u002Fdiv>`).\n    *   **HTML Attributes:** Use `esc_attr()` for data placed inside attributes (e.g., `\u003Cdiv class=\"\u003C?php echo esc_attr( $class ); ?>\">`).\n    *   **URLs:** Use `esc_url()` for links or image sources.\n    *   **Rich Text\u002FHTML:** Use `wp_kses()` or `wp_kses_post()` to allow only a specific set of safe HTML tags.\n\n3.  **Validate on the Server:**\n    Do not rely on client-side restrictions (like dropdown menus or predefined options). Always validate that the value received on the server matches the expected format or a whitelist of allowed values.\n\n### Remediation for CVE-2026-11380\n\nAs noted in the vulnerability description and the plugin's changelog, the fix involves ensuring that settings like `animation_effect` are properly escaped before being rendered inside an HTML class attribute. Developers should use `esc_attr()` when outputting such settings to prevent attribute injection.\n\nFor further information on securing WordPress plugins, you can consult the following resources:\n*   [WordPress Plugin Handbook: Security](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F)\n*   [OWASP Cross-Site Scripting (XSS) Prevention Cheat Sheet](https:\u002F\u002Fcheatsheetseries.owasp.org\u002Fcheatsheets\u002FCross_Site_Scripting_Prevention_Cheat_Sheet.html)","gemini-3-flash-preview","2026-07-25 12:59:18","2026-07-25 12:59:55",{"type":38,"vulnerable_version":39,"fixed_version":11,"vulnerable_browse":40,"vulnerable_zip":41,"fixed_browse":42,"fixed_zip":43,"all_tags":44},"plugin","1.0.21","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fjetwidgets-for-elementor\u002Ftags\u002F1.0.21","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjetwidgets-for-elementor.1.0.21.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fjetwidgets-for-elementor\u002Ftags\u002F1.0.22","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fjetwidgets-for-elementor.1.0.22.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fjetwidgets-for-elementor\u002Ftags"]