Extension WordPress

Vulnérabilités Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Cette page rassemble les failles publiées pour Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
0Critiques
19Avec correctif
8,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

19 fiches

CVE-2026-13710 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Kit for Elementor <= 3.2.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg_body_description' parameter in versions up to, and including, 3.2.6.…

Versions affectées

*-3.2.6

Correctif

3.2.7

Publication

09/07/2026

CVE-2026-6916 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Kit for Elementor <= 3.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_content_number_prefix' Shortcode Attribute

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sg_content_number_prefix' parameter in all versions up to, and including, 3.1.0 due to…

Versions affectées

*-3.1.0

Correctif

3.1.1

Publication

01/05/2026

CVE-2025-14275 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 3.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.0.1 due to insufficient input sanitization in the countdown widget's redirect functionality. This makes it possible for authenticated…

Versions affectées

*-3.0.1

Correctif

3.0.2

Publication

07/01/2026

CVE-2025-9978 Moyenne · 5,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Kit for Elementor – Powerful Elementor Addons, Widgets & Templates for WordPress < 2.6.9 – Authenticated (Author+) Stored Cross-Site Scripting via SVG

The Jeg Kit for Elementor – Powerful Elementor Addons, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.9 due to insufficient…

Versions affectées

*-2.6.9

Correctif

2.7.0

Publication

03/10/2025

CVE-2025-2944 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.12 – Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up to, and including, 2.6.12 due to insufficient input sanitization and output escaping on…

Versions affectées

*-2.6.12

Correctif

2.6.13

Publication

09/05/2025

CVE-2024-13217 Moyenne · 4,3
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.11 – Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

*-2.6.11

Correctif

2.6.12

Publication

26/02/2025

CVE-2024-10308 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via JKit – Countdown Widget

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit – Countdown widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-2.6.9

Correctif

2.6.10

Publication

25/11/2024

CVE-2024-8899 Moyenne · 4,3
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.9 – Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

*-2.6.9

Correctif

2.6.10

Publication

25/11/2024

CVE-2024-47390 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.6.8

Correctif

2.6.9

Publication

30/09/2024

CVE-2024-6804 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.7 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.6.7

Correctif

2.6.8

Publication

26/08/2024

CVE-2024-4479 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via JKit – Tabs and JKit – Accordion Widgets

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit – Tabs and JKit – Accordion widget, respectively, in all versions up to, and including,…

Versions affectées

*-2.6.5

Correctif

2.6.6

Publication

14/06/2024

CVE-2024-0334 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.4 – Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget URL Custom Attributes

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attribute of a link in several Elementor widgets in all versions up to, and including, 2.6.4 due to insufficient input sanitization and…

Versions affectées

*-2.6.4

Correctif

2.6.5

Publication

30/04/2024

CVE-2024-3161 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attributes in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.6.4

Correctif

2.6.5

Publication

30/04/2024

CVE-2024-3819 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via JKit – Banner

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit – Banner widget in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-2.6.4

Correctif

2.6.5

Publication

26/04/2024

CVE-2024-3162 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attributes in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.6.3

Correctif

2.6.4

Publication

02/04/2024

CVE-2024-1327 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.6.3

Correctif

2.6.4

Publication

02/04/2024

CVE-2024-1326 Moyenne · 6,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

27/02/2024

CVE-2022-3805 Élevée · 8,6
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.5.6 – Unauthenticated Authorization Bypass

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from…

Versions affectées

*-2.5.6

Correctif

2.5.7

Publication

04/11/2022

CVE-2022-3794 Moyenne · 5,4
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Jeg Elementor Kit <= 2.5.6 – Authorization Bypass

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make…

Versions affectées

*-2.5.6

Correctif

2.5.7

Publication

04/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités