CVE-2024-2974: Wpdeveloper Essential Addons For Elementor
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.
Affected products
- Wpdeveloper Essential Addons For Elementor: before 5.9.14 (fixed in 5.9.14)
Published 2024-04-09. Last modified 2026-06-17.