CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-2916

mediumCVSS 4.3covered by 1 sourcefirst seen 2026-08-01
The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the enqueue_scripts() method in class/dashboard/class-dashboard.php. The plugin injects a JkitDashboardOption JavaScript object containing full plugin inventory (names, versions, paths, active status), system environment details (WordPress version, PHP version, site URLs, server capabilities), and potentially third-party API credentials (Mailchimp API key via jkit_user_data) as an inline script on the post.php admin page. Because this data is output without any capability check beyond post editing access, any authenticated user with Contributor-level access or above can view this sensitive configuration data by inspecting the page source. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive site configuration data, installed plugin details, and potentially third-party API keys.

⚡ Watch CVE-2026-2916

Get an email if CVE-2026-2916 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-2916

CVE.org record

Embed the live status

CVE-2026-2916 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-2916 status](https://www.csirts.com/badge/CVE-2026-2916)](https://www.csirts.com/cve/CVE-2026-2916)