The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2022-12-22T20:27:09.193Z
Updated: 2024-08-03T01:20:58.421Z
Reserved: 2022-11-01T15:03:02.666Z
Link: CVE-2022-3794
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-22T21:15:10.227
Modified: 2023-11-07T03:51:48.460
Link: CVE-2022-3794
Redhat
No data.