PT-2026-47130 · WordPress · Essential Addons For Elementor
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Essential Addons for Elementor versions prior to 6.6.5
Description
The plugin is subject to information exposure due to insufficient restrictions on the posts that can be included within the
ajax load more() function. This allows unauthenticated attackers to extract data from private, draft, or password-protected posts that should otherwise be inaccessible.Recommendations
Update to a version later than 6.6.4.
As a temporary workaround, consider restricting access to the
ajax load more() function until the update is applied.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Essential Addons For Elementor