SecAlerts
j

jegtheme

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 22, 2022 to present

20
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
42/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
3
Medium
17
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
15
2
Infoleak
1

Most Affected Products

1. Jegtheme Jeg Elementor Kit Wordpress16
2. Jegtheme Jeg Elementor Kit3
3. WordPress Jeg Elementor Kit3
4. Jegtheme Jeg Kit for Elementor2
5. Jegtheme Epic Review1

Recent Vulnerabilities

See more →
CVE-2026-18405
CVSS 7.2high

Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content

Sep 18, 2026🔧 No Patch
CVE-2026-13710
CVSS 6.4medium

Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget

Jul 10, 2026🔧 No Patch
CVE-2025-53573
CVSS 7.1high

WordPress Epic Review Plugin <= 1.0.2 - Cross Site Scripting (XSS) Vulnerability

Nov 6, 2025🔧 No Patch
CVE-2025-39373
CVSS 5.3medium

WordPress JNews theme <= 12.0.5 - Broken Access Control vulnerability

May 19, 2025🔧 No Patch
CVE-2024-13217
CVSS 4.3medium

Jeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas

Feb 27, 2025
CVE-2024-8899
CVSS 4.3EPSS 0%medium

Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template

Nov 26, 2024
CVE-2024-10308
CVSS 6.4medium

Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget

Nov 26, 2024
CVE-2024-47390
CVSS 6.5medium

WordPress Jeg Elementor Kit plugin <= 2.6.8 - Cross Site Scripting (XSS) vulnerability

Oct 5, 2024
CVE-2024-6804
CVSS 6.4EPSS 0%medium

Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File

Aug 27, 2024
CVE-2024-4479
CVSS 6.4EPSS 0%medium

Jeg Elementor Kit <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets

Jun 15, 2024🔧 No Patch

Monitor jegtheme in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

jegtheme Security Vulnerabilities & Risk Score | 20 CVEs | SecAlerts - SecAlerts