JetBlocks for Elementor

JetBlocks for Elementor has 11 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 11 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.3 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (45%). Other recurring categories include Missing Authorization, Exposure Of Sensitive Information To An Unauthorized Actor.

Every one of the 11 issues recorded for JetBlocks for Elementor has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, most of them (6) reported by stealthcopter.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

11

Get automatic notifications for all JetBlocks for Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.3CVE-2023-48760

Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization to Unauthenticated Unauthorized Action

Read the full analysis

Vulnerability Records

11 records
2026-08-01 00:00CVE-2026-61976
5.3
Medium
Ananda DhakalYes
2025-07-17 00:00CVE-2025-49934
6.4
Medium
stealthcopterYes
2025-07-16 00:00CVE-2025-53988
4.3
Medium
stealthcopterYes
2025-07-16 00:00CVE-2025-53989
6.4
Medium
stealthcopterYes
2025-04-17 00:00CVE-2025-39451
5.3
Medium
stealthcopterYes
2025-03-29 00:00CVE-2025-30987
6.4
Medium
stealthcopterYes
2024-08-15 00:00CVE-2024-7147
6.4
Medium
stealthcopterYes
2023-11-28 00:00CVE-2023-48762
4.3
Medium
Rafie MuhammadYes
2023-11-28 00:00CVE-2023-48756
6.1
Medium
Rafie MuhammadYes
2023-11-28 00:00CVE-2023-48760
7.3
High
Rafie MuhammadYes
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C