CVE-2026-2916
The Jeg Kit for Elementor plugin for WordPress contains a vulnerability that allows users with Contributor-level access or higher to view sensitive information about the plugin and the site's configuration. This information is exposed through a JavaScript object injected into the page source, which includes details such as plugin names, versions, and paths, as well as system environment information and potentially third-party API credentials. The vulnerability exists in all versions of the plugin up to and including 3.1.1, and can be accessed by inspecting the page source on the post.php admin page. As a result, attackers with sufficient access can extract sensitive data and potentially use it for malicious purposes.
Based on public CVE data (MITRE/NVD).