CVE · Medium

CVE-2022-3794 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3794 Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.5.7 2.5.7 2022-11-04

CVE-2022-3794

The Jeg Elementor Kit plugin for WordPress versions below 2.5.7 contains a broken authentication flaw that allows attackers to execute actions restricted to higher-privileged users, potentially leading to unauthorized administrator access. This vulnerability was identified by Ramuel Gall and has been patched in version 2.5.7 and later. Users should update their installations immediately to prevent exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.