Executive brief
Ultimate Store Kit Elementor Addons, a WordPress plugin used to build e-commerce store layouts, contains a security flaw that allows unauthorized individuals to access sensitive system information. An attacker could exploit this to view data that is normally restricted, potentially gaining insights into the website's configuration or user details. This information could be used to facilitate more advanced attacks against the site.
Technical details
The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to sensitive data exposure (CWE-497) in versions up to and including 3.0.5. The vulnerability allows an unauthenticated remote attacker to access sensitive information that should be restricted to authorized users. This occurs due to insufficient access controls or improper handling of system information within the plugin's components. Attackers can leverage this exposure to gather intelligence for further exploitation. The issue is addressed in version 3.0.7.
Affected products
- BdThemes Ultimate Store Kit Elementor Addons <= 3.0.5
Timeline
- 2026-01-25: disclosed: Reported by Bao - BlueRock
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: patched: NVD publication date; patch available in 3.0.7