CVE-2026-2916: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
The Jeg Kit for Elementor WordPress plugin up to version 3.1.1 exposes sensitive information via an inline JavaScript object on the post.php admin page. This object includes plugin inventory details, system environment data, and potentially third-party API keys. Any authenticated user with Contributor-level access or higher can view this data by inspecting the page source, as there is no proper capability check beyond post editing access.
AI Analysis
Technical Summary
CVE-2026-2916 describes a sensitive information exposure vulnerability in the Jeg Kit for Elementor plugin for WordPress. The vulnerability occurs in the enqueue_scripts() method of class-dashboard.php, where a JavaScript object named JkitDashboardOption is injected into the post.php admin page. This object contains detailed plugin inventory (names, versions, paths, active status), system environment information (WordPress and PHP versions, site URLs, server capabilities), and potentially sensitive third-party API credentials such as a Mailchimp API key. Because the plugin does not enforce sufficient capability checks beyond requiring post editing permissions, any authenticated user with Contributor-level access or above can access this sensitive data by viewing the page source, potentially leading to unauthorized disclosure of site configuration and credentials.
Potential Impact
The vulnerability allows authenticated users with Contributor-level or higher privileges to access sensitive configuration data, including installed plugin details and potentially third-party API keys. This exposure could facilitate further attacks or unauthorized access if the leaked information is leveraged by attackers. However, the vulnerability does not allow privilege escalation or denial of service directly.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict Contributor-level access to trusted users only and monitor for updates from the vendor. Avoid exposing sensitive API keys in plugin configurations accessible to lower-privileged users.
CVE-2026-2916: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
Description
The Jeg Kit for Elementor WordPress plugin up to version 3.1.1 exposes sensitive information via an inline JavaScript object on the post.php admin page. This object includes plugin inventory details, system environment data, and potentially third-party API keys. Any authenticated user with Contributor-level access or higher can view this data by inspecting the page source, as there is no proper capability check beyond post editing access.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-2916 describes a sensitive information exposure vulnerability in the Jeg Kit for Elementor plugin for WordPress. The vulnerability occurs in the enqueue_scripts() method of class-dashboard.php, where a JavaScript object named JkitDashboardOption is injected into the post.php admin page. This object contains detailed plugin inventory (names, versions, paths, active status), system environment information (WordPress and PHP versions, site URLs, server capabilities), and potentially sensitive third-party API credentials such as a Mailchimp API key. Because the plugin does not enforce sufficient capability checks beyond requiring post editing permissions, any authenticated user with Contributor-level access or above can access this sensitive data by viewing the page source, potentially leading to unauthorized disclosure of site configuration and credentials.
Potential Impact
The vulnerability allows authenticated users with Contributor-level or higher privileges to access sensitive configuration data, including installed plugin details and potentially third-party API keys. This exposure could facilitate further attacks or unauthorized access if the leaked information is leveraged by attackers. However, the vulnerability does not allow privilege escalation or denial of service directly.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict Contributor-level access to trusted users only and monitor for updates from the vendor. Avoid exposing sensitive API keys in plugin configurations accessible to lower-privileged users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-02-20T20:43:39.814Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6e4839bf32cb7a342e5785
Added to database: 08/01/2026, 19:25:45 UTC
Last enriched: 08/01/2026, 19:26:17 UTC
Last updated: 08/01/2026, 19:46:29 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.