Description
Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4.
Published: 2026-02-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch Now
AI Analysis

Impact

The issue involves the accidental insertion of sensitive information into data sent by the WPVibes Elementor Addon Elements plugin. Attackers who can interact with the plugin’s outputs can retrieve confidential data that was never intended for public exposure. This is classed as a CWE‑201 vulnerability, which describes insecure data handling that results in information disclosure. No arbitrary code execution or denial of service is possible; the impact is limited to the unintended reveal of sensitive data, potentially compromising application integrity or user privacy.

Affected Systems

WordPress sites that have installed the Elementor Addon Elements plugin from any unsupplied version through version 1.14.4 are affected. The vulnerability exists across all platform configurations that enable the plugin to process and return data to end users, including those that may expose configuration values or user credentials.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to trigger the plugin’s data output mechanism—most likely through normal user interactions or crafted HTTP requests—to read the exposed data. Because the data is publicly sent by the plugin, once the exploit is known, exposure can affect any user of the compromised site. The lack of remote code execution limits the damage vector, but confidentiality is still at risk.

Generated by OpenCVE AI on April 15, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Elementor Addon Elements plugin to the latest version (1.14.5 or later) to remove the vulnerability.
  • If an update is not immediately available, disable the Elementor Addon Elements plugin until the fix is released to prevent data exposure.
  • Review and sanitize any configuration files or hidden fields that may be inadvertently exposed by the plugin, ensuring sensitive data is not included in outbound responses.

Generated by OpenCVE AI on April 15, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Feb 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpvibes
Wpvibes elementor Addon Elements
Vendors & Products Wordpress
Wordpress wordpress
Wpvibes
Wpvibes elementor Addon Elements

Thu, 26 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4.
Title WordPress Elementor Addon Elements plugin <= 1.14.4 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Wordpress Wordpress
Wpvibes Elementor Addon Elements
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:15:09.215Z

Reserved: 2026-02-25T12:14:12.838Z

Link: CVE-2026-28131

cve-icon Vulnrichment

Updated: 2026-02-27T17:56:47.379Z

cve-icon NVD

Status : Deferred

Published: 2026-02-26T09:16:15.050

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-28131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T00:00:14Z

Weaknesses