Impact
The Jeg Kit for Elementor plugin (up to 3.1.1) injects a JavaScript object named JkitDashboardOption into the post editing page. This object contains full plugin inventory, WordPress and PHP version, site URLs, server capabilities, and may even expose third‑party API keys such as a Mailchimp key. The data is output without a strict capability check, so any authenticated user with Contributor-level access or higher can view it by inspecting the page source, resulting in a CWE‑200 information disclosure.
Affected Systems
All installations of Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress with versions 3.1.1 or earlier are affected. The vulnerability resides in the class/dashboard/class-dashboard.php file and applies to every site using the plugin in those releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate baseline risk. The EPSS score of less than 1% shows that exploitation is unlikely in the current threat landscape, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated with Contributor-level privileges or higher and exploit the inline script on the post.php admin page to extract the exposed configuration data. No additional privileges or network access beyond normal post editing are required.
OpenCVE Enrichment