The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to extract sensitive data including post/page ids and titles including those of with pending/draft/future/private status.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Elementor_addon_elements | Webtechstreet | * | 1.12.7 (including) |