All-in-One Addons for Elementor – WidgetKit
cpe:2.3:a:themesgrove:all-in-one_addons_for_elementor:*:*:*:*:wordpress:*:*
- <= 2.5.4
A vulnerability allowing sensitive information exposure has been identified in the All-in-One Addons for Elementor – WidgetKit plugin for WordPress. This issue affects all versions through 2.5.4 and is located in the elements/advanced-tab/template/view.php file. The vulnerability allows authenticated attackers with Contributor-level access and above to access sensitive data from private, pending, and draft templates.
Exploitation of this vulnerability could lead to unauthorized access to sensitive template data, including private, pending, and draft information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.