cleantalk
Vulnerabilities and Security Researches

Jeg Elementor Kit, CVE-2022-3805

CVE, Research URL

CVE-2022-3805

Application

Jeg Elementor Kit

Published on
Dec 23, 2022
Research Description
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.
Affected versions
Min -, max 2.5.7.
Status
vulnerable