WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin是一个应用插件。 WordPress plugin Premium Addons for Elementor 4.11.53及之前版本存在安全漏洞,该漏洞源于get_template_content函数缺少能力检查,可能导致未经授权的数据访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| leap13 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | * ~ 4.11.53 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Premium Addons for Elementor plugin for WordPress version 4.11.53 and below contains an unauthenticated information disclosure vulnerability.The vulnerability exists due to a missing authorization check in the get_template_content() AJAX handler, allowing unauthenticated attackers to retrieve private, draft, and pending Elementor templates that may contain sensitive information such as API keys, credentials, customer data,or unpublished content. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-14155.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet