PatchSiren

jegtheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH jegtheme CVE published 2026-08-06

CVE-2026-65549

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:16.877Z and has not been modified since then. A PHP object injection vulnerability exists in Jeg Kit for Elementor version 3.2.10 or earlier. The vulnerability is classified as CWE-502. This vulnerability could allow an attacker to inject malicious PHP objects, potentially leading to arbitr [truncated]

MEDIUM jegtheme CVE published 2026-08-01

CVE-2026-2916

The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1. Authenticated users with Contributor-level access or above can view sensitive configuration data by inspecting the page source on the post.php admin page. This exposure allows them to extract sensitive site configuration data, installed plugin details, and potentially [truncated]

MEDIUM jegtheme CVE published 2026-07-10

CVE-2026-13710

The Jeg Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg_body_description' parameter in versions up to, and including, 3.2.6. This is due to insufficient input sanitization and output escaping on the description attribute in the render_body() method of the Image_Box_View class. Authenticated attackers with Contributor-level access and above [truncated]