Elementor Addons AI Addons Information Exposure Vulnerability
Vulnerability
A vulnerability allowing information exposure has been identified in the Elementor Addons AI Addons plugin for WordPress, specifically in versions through 2.2.1. The issue arises in the 'render' function, where inadequate restrictions allow authenticated attackers with Contributor-level access or higher to access and extract data from private or draft templates that should be off-limits.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information contained in private or draft templates, allowing attackers to disclose data they should not have access to.
Reproduction
To reproduce this vulnerability, an authenticated user with Contributor-level access or higher can use the Elementor AI Addons plugin. The user can create or access a private or draft template and then utilize the 'AI Accordion' or 'AI Tab' widgets from the affected plugin. The vulnerability will be triggered when the widget is rendered, as the insufficient restrictions will allow access to the restricted template data.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
