CVE · Medium

CVE-2024-8899 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.6.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8899 Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.6.10 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 2.6.10 2.6.10 2024-11-25

CVE-2024-8899

Authenticated users with contributor or higher privileges can exploit a vulnerability in the Jeg Elementor Kit plugin for WordPress, which affects versions up to 2.6.9. The issue arises from the render_content function within class/elements/views/class-tabs-view.php, leading to unauthorized exposure of sensitive template data. This includes private, pending, and draft information that is not intended for public access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.