Description
The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.
Problem types
Product status
* (semver)
Timeline
| 2026-01-05: | Vendor Notified |
| 2026-01-15: | Disclosed |
Credits
shrikant bhosale
References
www.wordfence.com/...-e2b9-40c7-9de5-cff175fa10a5?source=cve
plugins.trac.wordpress.org/...cludes/Traits/Ajax_Handler.php
plugins.trac.wordpress.org/...cludes/Traits/Ajax_Handler.php
plugins.trac.wordpress.org/...cludes/Traits/Ajax_Handler.php
plugins.trac.wordpress.org/...cludes/Traits/Ajax_Handler.php
plugins.trac.wordpress.org/...cludes/Traits/Ajax_Handler.php
github.com/...ommit/4e43db06bcf12870cc3b185ed59b3fe2cd227945