CVE-2025-9978: Unknown Jeg Kit For Elementor

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.

Affected products

  • Unknown Jeg Kit For Elementor: before 2.7.0 (fixed in 2.7.0)

Published 2025-10-24. Last modified 2026-10-08.