Sensitive Information Exposure in Jeg Elementor Kit for WordPress
CVE-2024-13217
4.3MEDIUM
What is CVE-2024-13217?
The Jeg Elementor Kit plugin for WordPress presents a vulnerability that allows authenticated attackers with Contributor-level access or higher to access sensitive information. Through exploited functions such as 'expired_data' and 'build_content', attackers can retrieve private template data, including pending, scheduled, and draft content. This exposure can lead to unauthorized access to crucial data, compromising the privacy and intended security of user-generated templates.
Affected Version(s)
Jeg Elementor Kit * <= 2.6.11