{"ok":true,"trend":{"id":814320,"platform":"mastodon","region":"global","key":"jeg kit for elementor, a wordpress add-on on 300,000+ sites, has an unauthenticated stored xss: a stranger can plant jav","title":"Jeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant Jav","url":"https://infosec.exchange/@suriq/117374797688312635","first_seen":"2026-10-03T03:58:25.647968Z","last_seen":"2026-10-03T03:58:25.647968Z","last_rank":10,"peak_rank":10,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.81875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Jeg Kit for Elementor, a WordPress add-on installed on more than 300,000 sites, contains an unauthenticated stored cross-site scripting vulnerability, tracked as CVE-2026-100180. An attacker can inject JavaScript through a blog comment, which then runs in visitors' browsers. All versions up to 3.2.19 are affected, and site owners are urged to update to version 3.2.20 immediately.","why":"Security researchers are warning WordPress site owners to patch quickly because the flaw can be exploited by anyone without login on widely used sites.","tone":"neutral","entities":["Jeg Kit for Elementor","WordPress","Elementor"],"summarized_at":"2026-10-03T03:59:22.226416Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":901},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"WordPress plugin Jeg Kit vulnerable to stored XSS flaw","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-03T03:58:25.647968Z","rank":10,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@suriq/117374797688312635","author":"suriq@infosec.exchange","title":null,"snippet":"Jeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant JavaScript through a blog comment (CVE-2026-100180). Affects versions up to 3.2.19. Fix: update to 3.2.20. https:// suriq.io/blog/jeg-elementor-ki…","posted_at":"2026-10-03T03:14:39Z","likes":1}],"elsewhere":[],"window":"7d"}}