Record summary

CVE-2022-3805 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 3, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Browse jegtheme / Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

Default status: unaffected

CVE ListThrough 2.5.6affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHJeg Elementor Kit < 2.5.7 - Unauthenticated Settings UpdateCVSS 8.6

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

Impact

Unauthenticated attackers can exploit authorization bypass using easily obtained nonces to update plugin settings including MailChimp API keys, global styles, and 404 page configurations, potentially compromising site integrations and design.

Remediation

Fixed in 2.5.7

WeaknessesCWE-79
AuthorsDhiyaneshDk, popcorn94
Template tagscvecve2022wordpresswpwp-pluginjeg-elementor-kitvkevunauthintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CPE: cpe:2.3:a:jegtheme:jeg_elementor_kit:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/jeg-elementor-kit"
FOFA: body="/wp-content/plugins/jeg-elementor-kit/"

Source: ProjectDiscovery

References

5