Impact
The Jeg Kit for Elementor plugin up to and including version 3.2.10 contains a PHP Object Injection flaw that allows malicious input to be deserialized during normal operation. By sending crafted data that is unserialized, an attacker could instantiate arbitrary PHP objects. This vulnerability falls under CWE-502 and could enable remote code execution or modification of sensitive data, depending on the classes that are instantiated by the flaw.
Affected Systems
WordPress sites that have the Jeg Kit for Elementor plugin installed with a version less than or equal to 3.2.10 are affected. The plugin is maintained by Jeg Theme and is used to embed Elementor elements. Any site that has not upgraded to 3.2.11 or later remains vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. While the EPSS score is not reported, the lack of a KEV listing does not diminish the potential for exploitation. The likely attack vector is remote and can be triggered through normal HTTP requests or administrative functions that accept serialized data. Once the vulnerability is leveraged, an attacker can potentially execute arbitrary PHP code or tamper with site data.
OpenCVE Enrichment