CVE · High

CVE-2022-3805 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3805 Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7 Authorization Bypass Through User-Controlled Key High 7.5 < 2.5.7 2.5.7 2022-11-04

CVE-2022-3805

The Jeg Elementor Kit plugin contains an authorization bypass vulnerability affecting versions 2.5.6 and earlier that allows unauthenticated attackers to modify critical plugin settings including the MailChimp API key, global styles, 404 page configuration, and element enablement. The flaw stems from improper authorization checks in multiple functions that handle settings updates, and attackers can exploit this by obtaining a nonce value that is publicly available on pages using the plugin. This vulnerability was resolved in version 2.5.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.