Unauthorized Data Access in WPZOOM Addons for Elementor Plugin by WPZOOM
CVE-2026-2295
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 February 2026
What is CVE-2026-2295?
The WPZOOM Addons for Elementor plugin facilitates unauthorized access to sensitive data, specifically draft, future, and pending post titles and excerpts. This occurs due to a missing capability check within the 'ajax_post_grid_load_more' function, affecting all versions up to 1.3.2. As a result, unauthenticated attackers can exploit this flaw, compromising the integrity of data meant to remain restricted, thereby exposing private content that should not be available to users who are not logged in.
Affected Version(s)
WPZOOM Addons for Elementor β Starter Templates & Widgets 0 <= 1.3.2