What the vulnerability does
01Description
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
Explanation of Vulnerability in Simple Terms
Jeg Kit for Elementor versions up to 3.2.10 contain a deserialization vulnerability in how the plugin processes untrusted data. An authenticated administrator can craft malicious serialized input to execute arbitrary PHP code on the site. This requires high-level admin access and affects confidentiality, integrity, and availability of the WordPress installation.
What an attacker can do
Run arbitrary PHP code on the site with full site privileges.
Potential impact on your site
A compromised admin account can fully compromise your site, steal data, modify content, or install backdoors.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities