Impact
The vulnerability arises from the Essential Addons for Elementor plugin lacking authorization checks when resolving WooCommerce products in its comparison feature. Unauthenticated visitors can retrieve product details—title, price, and SKU—for products in draft, pending, or private status, which are normally hidden. The weakness is categorized as CWE-639, reflecting an improper authorization failure.
Affected Systems
The flaw affects the Essential Addons for Elementor WordPress plugin on any installation running a version earlier than 6.6.10. No other versions are listed as affected in the CNA data. The issue specifically pertains to the WooCommerce integration bundled with the plugin.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as medium severity, and the EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. Because the attack vector is unauthenticated, an attacker only needs to access the product comparison page. The vulnerability is not listed in CISA's KEV catalog, so no public exploit is confirmed. Nevertheless, organizations that expose draft or private product data should assess the business impact of potential information leakage.
OpenCVE Enrichment