{
 "id": "WPSEC-2026-0685",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0685/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0685/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0685/index.md",
 "title": "Jeg Kit for Elementor <= 3.2.20 - Authenticated (Subscriber+) Missing Authorization to User Enumeration via Element Option and Author Search AJAX Actions",
 "description": "The Jeg Kit for Elementor plugin for WordPress is vulnerable to unauthorized access of data via the element option AJAX actions (get_ajax_option) and the 'jeg_find_author' AJAX action (find_ajax_author) in all versions up to, and including, 3.2.20, due to missing capability checks. The element option handler returns each element's field configuration to any logged-in user, including the nonce for the author search. The author search handler checks only that nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to search all site users by login, nicename, email address or URL and get back their user IDs and display names. Matching searches against the email column also lets them work out users' email addresses.",
 "plugin": {
  "slug": "jeg-elementor-kit",
  "name": "Jeg Kit for Elementor",
  "full_name": "Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/jeg-elementor-kit/",
  "advisories_url": "https://wpsec.com/vuln/plugin/jeg-elementor-kit/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/jeg-elementor-kit"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.2.21",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.2.21"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.2.21",
 "remediation": "Update to 3.2.21 or later.",
 "fix_released": "2026-10-08T13:41:51+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:52:52.236838+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0685/",
  "https://plugins.svn.wordpress.org/jeg-elementor-kit/tags/3.2.21/",
  "https://wordpress.org/plugins/jeg-elementor-kit/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/jeg-elementor-kit",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-10"
 }
}