Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security weaknesses in Jeg Kit for Elementor, a WordPress plugin offering powerful addons, widgets, and templates. It aggregates vulnerability data to provide a centralized view of security risks associated with this specific vendor and product ecosystem. The content collected spans a wide range of common weakness types, including SQL injection, cross-site scripting, and improper access control issues that may affect website integrity. The time range covered includes all disclosed vulnerabilities from the plugin’s initial release up to the present date, ensuring a comprehensive historical perspective on its security posture. This allows researchers and administrators to analyze trends in vulnerability discovery and remediation over time. Readers can use this resource to track the vendor’s security advisories and see how quickly patches are issued for reported issues. You can also understand the specific weakness classes that frequently impact this product, helping you prioritize security audits based on real-world exposure. Additionally, users can look up the product’s complete vulnerability history to assess long-term stability and make informed decisions about upgrading or replacing the plugin. This aggregation supports both proactive threat hunting and reactive incident response by consolidating fragmented security information into a single, accessible reference point for WordPress developers and site owners.

Vendor: jegtheme

CVE IDTitleCVSSSeverityPublished
CVE-2026-6916 Jeg Kit for Elementor <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_content_number_prefix' Shortcode Attribute CWE-79 6.4 Medium2026-05-02
CVE-2025-14275 Jeg Elementor Kit <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget CWE-79 6.4 Medium2026-01-08
CVE-2025-2944 Jeg Elementor Kit <= 2.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Button and Countdown Widgets CWE-79 6.4 Medium2025-05-10
CVE-2024-13217 Jeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-Canvas CWE-359 4.3 Medium2025-02-27
CVE-2024-10308 Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget CWE-79 6.4 Medium2024-11-26
CVE-2024-8899 Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template CWE-200 4.3 Medium2024-11-26
CVE-2024-6804 Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File CWE-79 6.4 Medium2024-08-27
CVE-2024-4479 Jeg Elementor Kit <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets CWE-79 6.4 Medium2024-06-15
CVE-2024-3161 Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget CWE-79 6.4 Medium2024-05-02
CVE-2024-3819 Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner CWE-79 6.4 Medium2024-05-02
CVE-2024-0334 Jeg Elementor Kit <= 2.6.4 - Authenticated (Contributor+) Cross-Site Scripting via Elementor Widget URL Custom Attributes CWE-79 6.4 Medium2024-05-01
CVE-2024-3162 Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial CWE-87 6.4 Medium2024-04-03
CVE-2024-1327 Jeg Elementor Kit <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box CWE-79 6.4 Medium2024-04-03
CVE-2024-1326 Jeg Elementor Kit <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags CWE-79 6.4 Medium2024-03-12
CVE-2022-3794 Jeg Elementor Kit <= 2.5.6 - Authorization Bypass CWE-639 5.4 Medium2022-12-22
CVE-2022-3805 Jeg Elementor Kit <= 2.5.6 - Unauthenticated Authorization Bypass CWE-639 8.6 High2022-12-22

All 16 known CVE vulnerabilities affecting Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress with full Chinese analysis, references, and POCs where available.