The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function in class/elements/views/class-tabs-view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
We have discovered 14,375 live websites that are affected by CVE-2024-8899.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 14,375 live websites (52.19% of Jeg Elementor Kit install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 46 versions ( 92.00% of all versions) |
![]() | 4,761 websites |
![]() | 1,805 websites |
![]() | 905 websites |
![]() | 766 websites |
![]() | 755 websites |
![]() | 579 websites |
![]() | 507 websites |
![]() | 373 websites |
![]() | 256 websites |
![]() | 235 websites |
.com | 6,385 websites |
.com.br | 1,219 websites |
.de | 538 websites |
.org | 402 websites |
.es | 319 websites |
.pl | 309 websites |
.co.uk | 305 websites |
.net | 291 websites |
.fr | 287 websites |
.it | 235 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*******.**.il | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
***************.com | ![]() | ***,*** | |
*****************.***.sg | ![]() | ***,*** | |
*******.net | ![]() | ***,*** | |
*********.hk | ![]() | ***,*** | |
**********************.de | ![]() | ***,*** | |
**************.com | ![]() | ***,*** |
FAQ