CVE Feed

    Dashboard / CVE / CVE-2022-3794

    CVE-2022-3794

    The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.

    Published:Dec 22, 2022
    Last Modified:Apr 8, 2026
    EPS:Dec 22, 2022
    EPSS Score:0.00175
    CVSS Score:5.4

    Affected Products

    Vendor
    Jegtheme
    Product
    Jeg Elementor Kit

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High