The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
References
Configurations
History
25 Mar 2025, 13:29
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
First Time |
Jegtheme jeg Elementor Kit
Jegtheme |
|
CPE | cpe:2.3:a:jegtheme:jeg_elementor_kit:*:*:*:*:*:wordpress:*:* | |
Summary |
|
|
References | () https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/trunk/class/elements/views/class-countdown-view.php#L107 - Product | |
References | () https://plugins.trac.wordpress.org/browser/jeg-elementor-kit/trunk/class/elements/views/class-off-canvas-view.php#L25 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3246154/ - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/2136cad8-6b0b-4458-a357-6e98f1ac3e0b?source=cve - Third Party Advisory |
27 Feb 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 12:15
Updated : 2025-03-25 13:29
NVD link : CVE-2024-13217
Mitre link : CVE-2024-13217
CVE.ORG link : CVE-2024-13217
JSON object : View
Products Affected
jegtheme
- jeg_elementor_kit
CWE