CVE-2025-14155
Premium Addons for Elementor <= 4.11.53 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content'
Record summary
CVE-2025-14155 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 23, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Premium Addons for Elementor – Powerful Elementor Templates & WidgetsBrowse leap13 / Premium Addons for Elementor – Powerful Elementor Templates & WidgetsDefault status: unaffected | CVE List | Through 4.11.53 | affected |
premium_addons_for_elementorBrowse leap13 / premium_addons_for_elementor | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMPremium Addons for Elementor - Unauthenticated Information DisclosureCVSS 5.3
Premium Addons for Elementor plugin for WordPress version 4.11.53 and below contains an unauthenticated information disclosure vulnerability.The vulnerability exists due to a missing authorization check in the get_template_content() AJAX handler, allowing unauthenticated attackers to retrieve private, draft, and pending Elementor templates that may contain sensitive information such as API keys, credentials, customer data,or unpublished content.
Impact
Unauthenticated attackers can view private and unpublished template content, leading to sensitive data disclosure.
Remediation
Update to the latest version beyond 4.11.53.
Source: ProjectDiscovery