What is CVE-2026-2916?
This vulnerability affects the Jeg Kit for Elementor WordPress plugin up to version 3.1.1, allowing sensitive information exposure. The `enqueue_scripts()` method in `class/dashboard/class-dashboard.php` injects a `JkitDashboardOption` JavaScript object with full plugin details. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu boşluq Elementor üçün Jeg Kit WordPress plaginində 3.1.1-ə qədər olan versiyalarda həssas məlumat sızmasına səbəb olur. `class/dashboard/class-dashboard.php` faylındakı `enqueue_scripts()` metodu vasitəsilə `JkitDashboardOption` JavaScript obyektinə tam plagin məlumatları daxil edilir. Plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: WordPress
FAQ2
Which versions of the Jeg Kit plugin are affected by CVE-2026-2916?
This vulnerability affects the Jeg Kit for Elementor WordPress plugin up to version 3.1.1.
What information is exposed by the CVE-2026-2916 vulnerability?
The vulnerability causes sensitive information exposure by injecting a `JkitDashboardOption` JavaScript object with full plugin details via the `enqueue_scripts()` method in `class/dashboard/class-dashboard.php`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.