Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.2.
We have discovered 93,209 live websites that are affected by CVE-2026-24958.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 93,209 live websites (97% of Crocoblock JetElements install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 163 versions ( 99% of all versions) |
| 23,177 websites | |
| 9,906 websites | |
| 5,146 websites | |
| 4,502 websites | |
| 3,762 websites | |
| 3,750 websites | |
| 3,650 websites | |
| 3,083 websites | |
| 2,834 websites | |
| 2,211 websites |
| .com | 34,275 websites |
| .de | 6,196 websites |
| .com.br | 3,991 websites |
| .nl | 3,439 websites |
| .org | 3,240 websites |
| .fr | 2,360 websites |
| .it | 2,334 websites |
| .co.uk | 2,328 websites |
| .com.au | 1,684 websites |
| .pl | 1,667 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *** | ||
| ************.nl | *,*** | ||
| ******************.de | **,*** | ||
| ******************.com | **,*** | ||
| *****************.com | **,*** | ||
| **************.com | **,*** | ||
| ********.com | **,*** | ||
| ******.com | **,*** | ||
| **************.com | **,*** | ||
| *****************.org | **,*** |
FAQ