CVE-2025-14155CVSS 5.3Web
CVE-2025-14155: premium addons for elementor vulnerability
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.
- CVSS
- 5.3 MEDIUM
- EPSS
- 49.96%
- Known exploited
- not in KEV
- Product
- premium addons for elementor
What is known
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.