CVE-2024-8899CVSS 4.3Web
CVE-2024-8899: jeg elementor kit vulnerability
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
- CVSS
- 4.3 MEDIUM
- EPSS
- 32.62%
- Known exploited
- not in KEV
- Product
- jeg elementor kit
What is known
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.