What the vulnerability does
01Description
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Explanation of Vulnerability in Simple Terms
02Summary
The All-in-One Addons for Elementor – WidgetKit plugin through version 2.5.5 exposes sensitive information to authenticated users. A logged-in attacker with low privileges can access data they should not be able to view. The vulnerability requires network access but no user interaction. Update to a version newer than 2.5.5 to remediate.
What an attacker can do
03Attacker Capabilities
Read sensitive information accessible only to higher-privilege users or other site users.
Potential impact on your site
04Site Impact
User data or site configuration details may be exposed to low-privilege accounts, risking privacy violations.
Conditions required to exploit
05Prerequisites
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
March 8, 2025
CVE published
April 8, 2026
Record updated