CVE-2024-0334
- EPSS 0.21%
- Veröffentlicht 01.05.2024 13:15:48
- Zuletzt bearbeitet 15.01.2025 18:09:14
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attribute of a link in several Elementor widgets in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output esca...
CVE-2024-32721
- EPSS 0.29%
- Veröffentlicht 24.04.2024 10:15:06
- Zuletzt bearbeitet 22.01.2025 20:29:07
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.3.
CVE-2024-3162
- EPSS 0.23%
- Veröffentlicht 03.04.2024 03:15:10
- Zuletzt bearbeitet 15.01.2025 18:08:52
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attributes in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possib...
CVE-2024-1327
- EPSS 0.14%
- Veröffentlicht 03.04.2024 03:15:08
- Zuletzt bearbeitet 15.01.2025 18:08:20
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible f...
CVE-2024-1326
- EPSS 0.15%
- Veröffentlicht 21.03.2024 02:51:41
- Zuletzt bearbeitet 15.01.2025 18:08:01
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authent...
CVE-2024-29101
- EPSS 0.19%
- Veröffentlicht 19.03.2024 16:15:12
- Zuletzt bearbeitet 27.01.2025 16:21:01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2.
CVE-2022-3794
- EPSS 0.18%
- Veröffentlicht 22.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:20:15
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additio...
CVE-2022-3805
- EPSS 11.45%
- Veröffentlicht 22.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:20:16
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from p...