/Vulnerability Library

Premium Addons for Elementor - Unauthenticated Information Disclosure

CVE-2025-14155
Verified

Description

Premium Addons for Elementor plugin for WordPress version 4.11.53 and below contains an unauthenticated information disclosure vulnerability.The vulnerability exists due to a missing authorization check in the get_template_content() AJAX handler, allowing unauthenticated attackers to retrieve private, draft, and pending Elementor templates that may contain sensitive information such as API keys, credentials, customer data,or unpublished content.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

premium_addons_for_elementor

Published Date

February 10, 2026

Template Author

dhiyaneshdk

CVE-2025-14155.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-14155
CWE ID:
cwe-862

References

https://nvd.nist.gov/vuln/detail/CVE-2025-14155https://www.wordfence.com/threat-intel/vulnerabilities/id/135c33bb-5ec2-4697-9340-1d2651ff3a0b?source=cvehttps://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.53/includes/addons-integration.php#L1624https://plugins.trac.wordpress.org/changeset/3416254/

Remediation Steps

Update to the latest version beyond 4.11.53.