Description
WordPress Plugin JetWidgets for Elementor and WooCommerce is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin JetWidgets for Elementor and WooCommerce version 1.1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.8 or latest
References
Related Vulnerabilities
WordPress Plugin ThirstyAffiliates Affiliate Link Manager Cross-Site Scripting (3.9.2)
WordPress Plugin Listing, Classified Ads & Business Directory-uListing Arbitrary File Upload (1.2.1)
WP Plugin Contact Form 7 CVE-2018-20979 Vulnerability (CVE-2018-20979)
ReviveAdserver Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2025-52670)
SharePoint Out-of-bounds Read Vulnerability (CVE-2026-45485)