Education Addon for Elementor Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Education Addon for Elementor plugin for WordPress, affecting all versions through 1.3.1. The vulnerability arises from missing validation on a user-controlled key in the naedu_elementor_template shortcode. This flaw enables authenticated attackers with Contributor-level access and above to access and extract information from non-public posts, including drafts, password-protected content, and restricted posts. The issue specifically pertains to posts created with Elementor.

Impact

Exploitation of this vulnerability allows for unauthorized access to private post information, including drafts and password-protected content.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
5.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.