Description
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider.php and widgets/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
* (semver)
Timeline
| 2024-12-09: | Vendor Notified |
| 2024-12-17: | Disclosed |
Credits
Ankit Patel
References
www.wordfence.com/...-97f5-4368-a805-0f60d1b8ad11?source=cve
plugins.trac.wordpress.org/...animation-addons-for-elementor