Junglewise Threat Intelligence

CVE-2026-66438: Tim Strifler Exclusive Addons Elementor sensitive data exposure

CVE-2026-66438 · Severity: medium · CVSS 5.3 · Published 2026-07-27

Technologies: Tim Strifler Exclusive Addons for Elementor. Vendors: Tim Strifler.

Executive brief

A vulnerability in the Exclusive Addons Elementor plugin for WordPress allows unauthorized individuals to access sensitive system information. This plugin is used to add custom design elements and widgets to websites built with the Elementor page builder. An exploit could lead to the exposure of internal data that might help an attacker plan further, more targeted attacks against the website.

Technical details

The Exclusive Addons Elementor plugin for WordPress (versions <= 2.8.0) is vulnerable to sensitive data exposure (CWE-497). The flaw allows an unauthenticated remote attacker to access sensitive system information that should be restricted to authorized users. This occurs because the plugin fails to properly protect certain control spheres or data outputs from unauthorized access. An attacker can exploit this over the network without any user interaction or prior authentication. The issue is addressed in version 2.8.1.

Affected products

  • Tim Strifler Exclusive Addons Elementor <= 2.8.0

Timeline

  • 2026-07-14: other: Reported by researcher Ananda Dhakal via Patchstack
  • 2026-07-27: disclosed: Vulnerability published by Patchstack and NVD
  • 2026-07-27: patched: Fixed in version 2.8.1

References

Related threats