THREAT OPS › Threat News › [NVD] CVE-2026-2916 (MEDIUM 4.3) — The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the `enqueue_scripts()` method in `class/dashboard/class-dashboard.php`. The plugin injects a `JkitDashboardOption` JavaScript object con
[NVD] CVE-2026-2916 (MEDIUM 4.3) — The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the `enqueue_scripts()` method in `class/dashboard/class-dashboard.php`. The plugin injects a `JkitDashboardOption` JavaScript object con
CVE-2026-2916 CVSS: 4.3 MEDIUM Published: 2026-08-01T08:16:29.763
The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the `enqueue_scripts()` method in `class/dashboard/class-dashboard.php`. The plugin injects a `JkitDashboardOption` JavaScript object containing full plugin inventory (names, versions, paths
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-2916cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-2916