CVE-2024-8899

Jeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.


We have discovered 14,375 live websites that are affected by CVE-2024-8899.

Test my site




Affected Software

Product  Jeg Elementor Kit
Category Wordpress Plugins
Vulnerable Domains14,375 live websites (52.19% of Jeg Elementor Kit install base)
Vulnerable Versions
  • from 0 through 2.6.9
Vulnerable Versions Count46 versions ( 92.00% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Nov 26, 2024
  • Updated - Nov 26, 2024

Credits

  • Ankit Patel (finder)

CVE-2024-8899 usage by Country

United States4,761 websites



Germany1,805 websites
Cyprus905 websites
Brazil766 websites
France755 websites
Spain579 websites
GB507 websites
Poland373 websites
Italy256 websites
India235 websites

CVE-2024-8899 usage by TLD

.com6,385 websites
.com.br1,219 websites
.de538 websites
.org402 websites
.es319 websites
.pl309 websites
.co.uk305 websites
.net291 websites
.fr287 websites
.it235 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8899

Top websites that are affected by CVE-2024-8899. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States**,***
*******.com United States**,***
*******.**.il United States**,***
********.**.il Israel**,***
***************.com United States***,***
*****************.***.sg Singapore***,***
*******.net United States***,***
*********.hk Hong Kong***,***
**********************.de Germany***,***
**************.com United States***,***
See full domain list

FAQ

CVE-2024-8899 is Exposure of Sensitive Information to an Unauthorized Actor in Jeg Elementor Kit
A total of 14,375 websites have been identified as vulnerable to CVE-2024-8899, discovered through global website indexing conducted by WebTechSurvey.
Jeg Elementor Kit is susceptible to CVE-2024-8899 vulnerability.
Jeg Elementor Kit versions before, and including, 2.6.9 are vulnerable to CVE-2024-8899.