What the vulnerability does
01Description
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.
Explanation of Vulnerability in Simple Terms
02Summary
Jeg Kit for Elementor versions up to 2.5.6 contain an authorization flaw that allows authenticated users to read and modify data they should not have access to. The vulnerability requires a logged-in account but no special privileges. An attacker with basic user access can view or alter sensitive information stored by the plugin.
What an attacker can do
03Attacker Capabilities
Read and modify data belonging to other users or the site without proper authorization.
Potential impact on your site
04Site Impact
Any logged-in user can access and change sensitive plugin data, risking data leaks and site integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with at least subscriber-level access.
Key dates
06Disclosure timeline
December 22, 2022
CVE published
April 8, 2026
Record updated