The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jegtheme
Jegtheme jeg Elementor Kit |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:jegtheme:jeg_elementor_kit:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Jegtheme
Jegtheme jeg Elementor Kit |
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 27 Feb 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data. | |
Title | Jeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas | |
Weaknesses | CWE-359 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-27T14:31:58.621Z
Reserved: 2025-01-08T18:59:55.363Z
Link: CVE-2024-13217

Updated: 2025-02-27T14:31:54.634Z

Status : Analyzed
Published: 2025-02-27T12:15:34.857
Modified: 2025-03-25T13:29:59.130
Link: CVE-2024-13217

No data.