Medium severity5.4NVD Advisory· Published Dec 22, 2022· Updated Apr 8, 2026
CVE-2022-3794
CVE-2022-3794
Description
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/changesetnvdExploitThird Party Advisory
- wordpress.org/plugins/jeg-elementor-kit/nvdProductRelease NotesThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/84b616fa-ff64-49e8-8c4a-7d7bfdf758benvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/84b616fa-ff64-49e8-8c4a-7d7bfdf758benvd
News mentions
0No linked articles in our index yet.