The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions. This makes it possible for unauthenticated attackers to extract posts that may be in private or draft status.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32307 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions. This makes it possible for unauthenticated attackers to extract posts that may be in private or draft status.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00404}

epss

{'score': 0.00392}


Fri, 10 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Wpdeveloper
Wpdeveloper essential Addons For Elementor
Weaknesses CWE-922
CPEs cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wpdeveloper
Wpdeveloper essential Addons For Elementor

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T20:20:01.126Z

Reserved: 2024-04-12T18:55:38.885Z

Link: CVE-2024-3733

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:01.126Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-25T09:15:08.237

Modified: 2025-01-10T21:36:36.520

Link: CVE-2024-3733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.