WPZOOM Addons for Elementor
cpe:2.3:a:wpzoom:wpzoom_elementor_addons:*:*:*:*:wordpress:*:*
- <= 1.3.2
A vulnerability exists in the WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress, in all versions through 1.3.2. The issue arises from a missing capability check in the 'ajax_post_grid_load_more' function, allowing unauthenticated attackers to access protected post titles and excerpts (draft, future, pending) that should not be available to them.
Exploitation of this vulnerability leads to unauthorized access to protected post information, including titles and excerpts of drafts, future, and pending posts.
Users can update to version 1.3.3 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.