CVE-2025-14155
MEDIUM EXPLOITED NUCLEIPremium Addons for Elementor - Info Disclosure
Title source: llmExploitation Summary
CVE-2025-14155 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.
Nuclei Templates (1)
Premium Addons for Elementor - Unauthenticated Information Disclosure
MEDIUMVERIFIEDby DhiyaneshDk
References (5)
Core 5
Core References
Scores
CVSS v3
5.3
EPSS
0.0049
EPSS Percentile
66.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
VulnCheck KEV
2026-02-23
CWE
CWE-862
Status
published
Products (2)
leap13/Premium Addons for Elementor – Powerful Elementor Templates & Widgets
< 4.11.53
leap13/premium_addons_for_elementor
< 4.11.54
Published
Dec 23, 2025
Tracked Since
Feb 18, 2026