Jegtheme Jeg Elementor Kit
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Jegtheme Jeg Elementor Kit.
By the Year
In 2026 there have been 0 vulnerabilities in Jegtheme Jeg Elementor Kit. Last year, in 2025 Jeg Elementor Kit had 1 security vulnerability published. Right now, Jeg Elementor Kit is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 4.30 |
| 2024 | 13 | 5.98 |
| 2023 | 0 | 0.00 |
| 2022 | 2 | 7.00 |
It may take a day or so for new Jeg Elementor Kit vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Jegtheme Jeg Elementor Kit Security Vulnerabilities
Jeg Elementor Kit WP 2.6.11 SDE via expired_data, build_content
CVE-2024-13217
4.3 - Medium
- February 27, 2025
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
Privacy violation
Jeg Elementor Kit <=2.6.9 SIE via render_content
CVE-2024-8899
4.3 - Medium
- November 26, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Insecure Storage of Sensitive Information
Stored XSS in Jeg Elementor Kit <=2.6.9 Countdown widget
CVE-2024-10308
6.4 - Medium
- November 26, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdown widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Jeg Elementor Kit < 2.6.8 Stored XSS Vulnerability
CVE-2024-47390
- October 05, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme Jeg Elementor Kit jeg-elementor-kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through <= 2.6.8.
XSS
Jeg Elementor Kit WP XSS via SVG uploads 2.6.7
CVE-2024-6804
5.4 - Medium
- August 27, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
XSS
Stored XSS in Jeg Elementor Kit 2.6.5 via sg_* attributes
CVE-2024-4479
6.4 - Medium
- June 15, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs and JKit - Accordion widget, respectively, in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Jeg Elementor Kit <=2.6.4 WP Plugin XSS via JKit Banner widget
CVE-2024-3819
6.4 - Medium
- May 02, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Banner widget in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Stored XSS in Jeg Elementor Kit <2.6.4 Countdown Widget
CVE-2024-3161
6.4 - Medium
- May 02, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attributes in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Jeg Elementor Kit WP Plugin Stored XSS via Link Attribute (2.6.4)
CVE-2024-0334
6.4 - Medium
- May 01, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attribute of a link in several Elementor widgets in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Jeg Elementor Kit (2.6.3) Stored XSS via Improper Input Neutralization
CVE-2024-32721
5.4 - Medium
- April 24, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.3.
XSS
Stored XSS via Testimonial Widget in Jeg Elementor Kit <2.6.3
CVE-2024-3162
6.4 - Medium
- April 03, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attributes in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32721 is likely a duplicate of this issue.
Improper Neutralization of Alternate XSS Syntax
Stored XSS in Jeg Elementor Kit Plugin v<=2.6.3 via Image Box Widget
CVE-2024-1327
6.4 - Medium
- April 03, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
WP Jeg Elementor Kit XSS via HTML Tag attribs v<=2.6.2
CVE-2024-1326
6.4 - Medium
- March 21, 2024
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-29101 is likely a duplicate of this issue.
XSS
Jeg Elementor Kit XSS Stored XSS in Jeg Elementor Kit <2.6.2
CVE-2024-29101
5.4 - Medium
- March 19, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2.
XSS
Authorization Bypass in Jeg Elementor Kit v2.5.6 via Nonce
CVE-2022-3805
8.6 - High
- December 22, 2022
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.
Insecure Direct Object Reference / IDOR
Authorization Bypass in Jeg Elementor Kit <=2.5.6 via AJAX actions
CVE-2022-3794
5.4 - Medium
- December 22, 2022
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.
Insecure Direct Object Reference / IDOR
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Jegtheme Jeg Elementor Kit or by Jegtheme? Click the Watch button to subscribe.