CVE Database /
CVE-2022-3794
CVE · Medium
CVE-2022-3794 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3794
|
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 2.5.7
|
2.5.7 |
2022-11-04 |
—
|
CVE-2022-3794
The Jeg Elementor Kit plugin for WordPress versions below 2.5.7 contains a broken authentication flaw that allows attackers to execute actions restricted to higher-privileged users, potentially leading to unauthorized administrator access. This vulnerability was identified by Ramuel Gall and has been patched in version 2.5.7 and later. Users should update their installations immediately to prevent exploitation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings