CVE-2025-14155

MEDIUM EXPLOITED NUCLEI

Premium Addons for Elementor - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-14155 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.

Nuclei Templates (1)

Premium Addons for Elementor - Unauthenticated Information Disclosure
MEDIUMVERIFIEDby DhiyaneshDk

Scores

CVSS v3 5.3
EPSS 0.0049
EPSS Percentile 66.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2026-02-23
CWE
CWE-862
Status published
Products (2)
leap13/Premium Addons for Elementor – Powerful Elementor Templates & Widgets < 4.11.53
leap13/premium_addons_for_elementor < 4.11.54
Published Dec 23, 2025
Tracked Since Feb 18, 2026