Impact
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to. The flaw is a CWE‑639 Authorization Bypass Through User‑Controlled Input vulnerability; consequently, attackers can request content that is normally inaccessible, leading to the unauthorized disclosure of confidential site content.
Affected Systems
The flaw affects the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress. All releases up to and including version 6.6.4 are vulnerable, covering the 6.5.x and 6.6.x branches referenced in the vendor release notes.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability falls into the medium category. The EPSS score of 5% indicates a moderate likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack vector is likely unauthenticated for any visitor that can access the "load_more" endpoint; no specific user authentication or privilege is required to trigger the data leak.
OpenCVE Enrichment