Premium Addons for Elementor - Unauthenticated Information Disclosure
CVE-2025-14155
Verified
Description
Premium Addons for Elementor plugin for WordPress version 4.11.53 and below contains an unauthenticated information disclosure vulnerability.The vulnerability exists due to a missing authorization check in the get_template_content() AJAX handler, allowing unauthenticated attackers to retrieve private, draft, and pending Elementor templates that may contain sensitive information such as API keys, credentials, customer data,or unpublished content.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Affected Product
premium_addons_for_elementor
Published Date
February 10, 2026
Template Author
dhiyaneshdk
CVE-2025-14155.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-14155
CWE ID:
cwe-862
References
https://nvd.nist.gov/vuln/detail/CVE-2025-14155https://www.wordfence.com/threat-intel/vulnerabilities/id/135c33bb-5ec2-4697-9340-1d2651ff3a0b?source=cvehttps://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.53/includes/addons-integration.php#L1624https://plugins.trac.wordpress.org/changeset/3416254/
Remediation Steps
Update to the latest version beyond 4.11.53.