Unauthorized Data Access in WPZOOM Addons for Elementor Plugin by WPZOOM
CVE-2026-2295

5.3MEDIUM

What is CVE-2026-2295?

The WPZOOM Addons for Elementor plugin facilitates unauthorized access to sensitive data, specifically draft, future, and pending post titles and excerpts. This occurs due to a missing capability check within the 'ajax_post_grid_load_more' function, affecting all versions up to 1.3.2. As a result, unauthenticated attackers can exploit this flaw, compromising the integrity of data meant to remain restricted, thereby exposing private content that should not be available to users who are not logged in.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WPZOOM Addons for Elementor – Starter Templates & Widgets * <= 1.3.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.