Vulnerabilities > CVE-2024-8899 - Insecure Storage of Sensitive Information vulnerability in Jegtheme JEG Elementor KIT

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
jegtheme
CWE-922

Summary

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

Vulnerable Configurations

Part Description Count
Application
Jegtheme
71

Common Weakness Enumeration (CWE)