CVE Database /
CVE-2022-3805
CVE · High
CVE-2022-3805 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3805
|
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.5.7 |
Authorization Bypass Through User-Controlled Key |
High
7.5
|
< 2.5.7
|
2.5.7 |
2022-11-04 |
—
|
CVE-2022-3805
The Jeg Elementor Kit plugin contains an authorization bypass vulnerability affecting versions 2.5.6 and earlier that allows unauthenticated attackers to modify critical plugin settings including the MailChimp API key, global styles, 404 page configuration, and element enablement. The flaw stems from improper authorization checks in multiple functions that handle settings updates, and attackers can exploit this by obtaining a nonce value that is publicly available on pages using the plugin. This vulnerability was resolved in version 2.5.7.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings