Sensitive Information Exposure in Responsive Addons for Elementor by WordPress
CVE-2025-2228
5.7MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2025
What is CVE-2025-2228?
The Responsive Addons for Elementor plugin for WordPress has a vulnerability in the 'register_user' function that allows authenticated attackers with Contributor-level access or higher to expose sensitive user information. Specifically, this flaw enables the extraction of usernames and passwords of users who register through the Edit Login | Registration Form widget, especially when the newly registered user opens the email notification confirming their registration. This vulnerability affects all versions up to and including 1.6.8, and it poses a significant risk to user data integrity.
Affected Version(s)
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates * <= 1.6.8