Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections
Description
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Elementor Addon Elements plugin <=1.13.8 exposes private template data via data-table widget, allowing Contributor+ users to view sensitive content.
Vulnerability
The vulnerability exists in the Elementor Addon Elements plugin for WordPress in versions up to and including 1.13.8. It is located in the render_column function in modules/data-table/widgets/data-table.php. This function does not properly restrict access to template data, leading to sensitive information exposure. [1]
Exploitation
An attacker must have authenticated access with at least Contributor-level privileges. The attacker can exploit this by interacting with the data-table widget, which incorrectly renders private, pending, and draft template data. No further user interaction is required. [1]
Impact
Successful exploitation allows an authenticated attacker to extract sensitive information such as private, pending, and draft template data. This can lead to disclosure of confidential content that should not be visible to lower-privileged users. The confidentiality of the system is compromised. [1]
Mitigation
The plugin vendor has released version 1.14.5 which addresses this vulnerability. Users are advised to update to the latest version. For those who cannot update, consider restricting Contributor-level access or disabling the data-table widget until patched. [1]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=1.13.8
- wpvibes/Addon Elements for Elementor (formerly Elementor Addon Elements)v5Range: 0
Patches
1Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.