The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam essential Addons For Elementor |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam essential Addons For Elementor |
|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 08:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-16T13:44:34.348Z
Reserved: 2026-01-15T20:03:46.612Z
Link: CVE-2026-1004
Updated: 2026-01-16T13:44:30.809Z
Status : Awaiting Analysis
Published: 2026-01-16T09:16:21.407
Modified: 2026-01-16T15:55:12.257
Link: CVE-2026-1004
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:41:40Z
Weaknesses