WordPress Plugin Vulnerabilities

Essential Addons for Elementor < 6.6.5 - Unauthenticated Sensitive Information Exposure via load_more AJAX Handler

Description

The plugin is vulnerable to sensitive information exposure via the ajax_load_more AJAX handler due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password-protected, private, or draft posts that they should not have access to.

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Anirudh Makkar
Verified
No

Timeline

Publicly Published
2026-06-05 (about 1 month ago)
Added
2026-06-05 (about 1 month ago)
Last Updated
2026-06-05 (about 1 month ago)

Other