๐Ÿ” CVE Alert

CVE-2026-13345

MEDIUM 5.3

Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
5th

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.

Vendor unknown
Product essential addons for elementor
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown essential addons for elementor

Be the first to know when new medium vulnerabilities affecting unknown essential addons for elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Essential Addons for Elementor
0 < 6.6.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/45937bce-12db-4770-9f15-606c62469f6d/

Credits

Revanth Hari Narayana Matte WPScan