Description
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
Published: 2026-07-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated sensitive data exposure flaw allows anyone to read protected information from a WordPress site that hosts the Exclusive Addons Elementor plugin built by Tim Strifler. The vulnerability is caused by the plugin's failure to enforce proper authentication before retrieving data, leading to a loss of data confidentiality. The documented weakness corresponds to CWE‑497, which highlights improper handling of authenticated requests.

Affected Systems

Any WordPress installation using the Exclusive Addons Elementor plugin version 2.8.0 or earlier is affected. Installing or updating to a version equal to or greater than 2.8.1 removes the flaw. Sites that cannot upgrade should remove or disable the plugin to eliminate exposure.

Risk and Exploitability

The CVSS score of 5.3 classifies this as a moderate-severity issue. An EPSS score of less than 1% indicates that exploitation is unlikely at present, and the plugin is not listed in the CISA KEV catalog. Nevertheless, because the flaw is unauthenticated, any visitor can potentially trigger the vulnerability by sending a request to the plugin’s public endpoint, allowing an attacker to compromise the confidentiality of the site’s data.

Generated by OpenCVE AI on August 3, 2026 at 17:24 UTC.

Remediation

Vendor Solution

Update the WordPress Exclusive Addons Elementor Plugin to the latest available version (at least 2.8.1).


OpenCVE Recommended Actions

  • Update Exclusive Addons Elementor to version 2.8.1 or later.
  • If an immediate upgrade is not possible, disable or remove the plugin to prevent any exposure.
  • Configure WordPress to enforce role‑based access controls, ensuring that only authenticated users can view sensitive data through the plugin or the admin interface.

Generated by OpenCVE AI on August 3, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Timstrifler
Timstrifler exclusive Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Timstrifler
Timstrifler exclusive Addons For Elementor
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
Title WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Timstrifler Exclusive Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:17:29.817Z

Reserved: 2026-07-27T09:00:18.436Z

Link: CVE-2026-66438

cve-icon Vulnrichment

Updated: 2026-07-27T15:10:52.518Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:11.313

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-66438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere