CVE-2026-7665
MEDIUMEssential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-7665. PoCs published by anirudhmakkar.
AI-analyzed exploit summary The repository contains a functional Python PoC for CVE-2026-7665, an unauthenticated information disclosure vulnerability in Essential Addons for Elementor. The exploit demonstrates how an attacker can read private, draft, and password-protected WordPress posts by abusing the `ajax_load_more` handler.
Description
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
Exploits (1)
The repository contains a functional Python PoC for CVE-2026-7665, an unauthenticated information disclosure vulnerability in Essential Addons for Elementor. The exploit demonstrates how an attacker can read private, draft, and password-protected WordPress posts by abusing the `ajax_load_more` handler.
References (14)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N