Description
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.
Published: 2026-07-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the Essential Addons for Elementor plugin lacking authorization checks when resolving WooCommerce products in its comparison feature. Unauthenticated visitors can retrieve product details—title, price, and SKU—for products in draft, pending, or private status, which are normally hidden. The weakness is categorized as CWE-639, reflecting an improper authorization failure.

Affected Systems

The flaw affects the Essential Addons for Elementor WordPress plugin on any installation running a version earlier than 6.6.10. No other versions are listed as affected in the CNA data. The issue specifically pertains to the WooCommerce integration bundled with the plugin.

Risk and Exploitability

The CVSS score of 5.3 classifies the issue as medium severity, and the EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. Because the attack vector is unauthenticated, an attacker only needs to access the product comparison page. The vulnerability is not listed in CISA's KEV catalog, so no public exploit is confirmed. Nevertheless, organizations that expose draft or private product data should assess the business impact of potential information leakage.

Generated by OpenCVE AI on August 2, 2026 at 05:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Essential Addons for Elementor to version 6.6.10 or later, which implements proper visibility checks for the comparison feature.
  • Disable the plugin’s product comparison module or restrict its endpoint to authenticated users who have permission to view draft/private products.
  • Ensure WooCommerce is configured to hide draft or private product information from the front‑end, removing any direct exposure of such data by the CMS or other plugins.

Generated by OpenCVE AI on August 2, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.
Title Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
References

Subscriptions

Wordpress Wordpress
Wpdevteam Essential Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T17:12:56.492Z

Reserved: 2026-06-25T14:13:30.190Z

Link: CVE-2026-13345

cve-icon Vulnrichment

Updated: 2026-07-30T17:12:41.419Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:24:59.403

Modified: 2026-07-30T19:17:06.260

Link: CVE-2026-13345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key