CVE-2024-8899: Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the rendercontent function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8899?
CVE-2024-8899 is classified as a medium severity vulnerability due to its impact on sensitive information exposure.
How do I fix CVE-2024-8899?
To mitigate CVE-2024-8899, update the Jeg Elementor Kit plugin to version 2.6.10 or later.
Who is affected by CVE-2024-8899?
CVE-2024-8899 affects all versions of the Jeg Elementor Kit plugin for WordPress up to and including version 2.6.9.
What kind of attack does CVE-2024-8899 allow?
CVE-2024-8899 allows authenticated attackers with Contributor-level access to potentially access sensitive information.
What components are involved in CVE-2024-8899?
CVE-2024-8899 involves the render_content function located in class/elements/views/class-tabs-view.php.