CVE · Medium

CVE-2024-3733 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3733 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.9.16 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 5.9.16 5.9.16 2024-04-24

CVE-2024-3733

The Essential Addons for Elementor plugin through version 5.9.15 contains a sensitive information exposure vulnerability in three AJAX functions: ajax_load_more(), eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery(). Unauthenticated attackers can exploit this flaw to retrieve posts that are marked as private or in draft status, which should not be publicly accessible. The issue affects all versions prior to 5.9.16.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.