Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-3805
HistoryDec 22, 2022 - 9:15 p.m.

Authorization

2022-12-2221:15:00
PRIOn knowledge base
www.prio-n.com
8
elementor kit plugin
wordpress
vulnerability
authorization bypass
unauthenticated users
plugin settings
nonce
mailchimp api key
global styles
404 page settings
enabled elements

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.4%

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

CPENameOperatorVersion
jeg_elementor_kitlt2.5.7

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.4%

Related for PRION:CVE-2022-3805