CVE-2026-13345
Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
5th
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.
| Vendor | unknown |
| Product | essential addons for elementor |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown essential addons for elementor
Be the first to know when new medium vulnerabilities affecting unknown essential addons for elementor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Essential Addons for Elementor
0 < 6.6.10
References
Credits
Revanth Hari Narayana Matte WPScan