5.4

CVE-2022-3794

Exploit

Jeg Elementor Kit <= 2.5.6 - Authorization Bypass

Jeg Elementor Kit <= 2.5.6 - Authorization Bypass

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6.  Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.
Mögliche Gegenmaßnahme
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress: Update to version 2.5.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JegthemeJeg Elementor Kit SwPlatformwordpress Version < 2.5.7
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
Version *-2.5.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
security@wordfence.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2811758%40jeg-elementor-kit%2Ftrunk&old=2810568%40jeg-elementor-kit%2Ftrunk&sfp_email=&sfph_mail=
Third Party Advisory
Exploit
https://wordpress.org/plugins/jeg-elementor-kit/#developers
Third Party Advisory
Product
Release Notes
https://www.wordfence.com/threat-intel/vulnerabilities/id/84b616fa-ff64-49e8-8c4a-7d7bfdf758be
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/84b616fa-ff64-49e8-8c4a-7d7bfdf758be?source=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/84b616fa-ff64-49e8-8c4a-7d7bfdf758be
Third Party Advisory