Executive brief
Exclusive Addons Elementor is a popular extension for the WordPress Elementor page builder that adds custom design widgets. A security flaw in versions up to 2.7.9.9 allows unauthorized individuals to access sensitive information that is embedded within the site's data but should not be publicly visible. This could lead to the exposure of configuration details or other internal data, potentially aiding further attacks against the website.
Technical details
The Exclusive Addons Elementor plugin for WordPress is vulnerable to sensitive data exposure (CWE-201) in versions up to and including 2.7.9.9. The flaw occurs when the plugin inadvertently includes sensitive information in data sent to the client-side, which can be retrieved by an unauthenticated remote attacker. This is a network-based attack requiring no special privileges or user interaction. The vulnerability was addressed in version 2.8.0.
Affected products
- Tim Strifler Exclusive Addons Elementor up to 2.7.9.9
Timeline
- 2026-06-25: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-05: advisory: Published by Patchstack and NVD
- 2026-07-05: patched: Version 2.8.0 released to address the issue