Description
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
* (semver)
Timeline
2024-09-16: | Vendor Notified |
2024-11-25: | Disclosed |
Credits
Ankit Patel
References
www.wordfence.com/...-321a-4635-943f-785ffc34d851?source=cve
plugins.trac.wordpress.org/...eset/3193980/jeg-elementor-kit