CVE-2023-39157 CRITICAL

CVE-2023-39157: WordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)

Vendor Crocoblock
Product JetElements For Elementor
Weakness CWE-94 · Code injection
Published December 31, 2023
Last update April 28, 2026

CVSS base score

9.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.

Explanation of Vulnerability in Simple Terms

02Summary

JetElements For Elementor versions up to 2.6.10 contain a code injection vulnerability that allows authenticated users to run arbitrary PHP code on the site. An attacker with low-level access (such as a contributor or editor) can inject malicious code through the plugin's functionality. The vulnerability requires user interaction to trigger. Successful exploitation grants full control over site content and data.

What an attacker can do

03Attacker Capabilities

Run arbitrary PHP code on the site with the privileges of the web server.

Potential impact on your site

04Site Impact

An authenticated attacker can modify site content, steal data, create backdoors, or take full control of your WordPress installation.

Conditions required to exploit

05Prerequisites

Attacker must have a low-level user account (contributor or editor) and trick a site admin into visiting a malicious page or link.

Key dates

06Disclosure timeline

December 31, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE