Unauthorized Data Access in WPZOOM Addons for Elementor Plugin by WPZOOM
CVE-2026-2295
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 February 2026
What is CVE-2026-2295?
The WPZOOM Addons for Elementor plugin facilitates unauthorized access to sensitive data, specifically draft, future, and pending post titles and excerpts. This occurs due to a missing capability check within the 'ajax_post_grid_load_more' function, affecting all versions up to 1.3.2. As a result, unauthenticated attackers can exploit this flaw, compromising the integrity of data meant to remain restricted, thereby exposing private content that should not be available to users who are not logged in.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPZOOM Addons for Elementor β Starter Templates & Widgets * <= 1.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved