CVE-2025-0968: ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the getmegamenucontent() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0968?
CVE-2025-0968 is classified as a high severity vulnerability due to its potential for sensitive information exposure.
How do I fix CVE-2025-0968?
To fix CVE-2025-0968, update the ElementsKit Elementor addons plugin to version 3.4.1 or later.
Who is affected by CVE-2025-0968?
CVE-2025-0968 affects all versions of the ElementsKit Elementor addons plugin for WordPress up to and including version 3.4.0.
What type of vulnerability is CVE-2025-0968?
CVE-2025-0968 is a vulnerability that allows for sensitive information exposure due to inadequate capability checks.
Can unauthenticated users exploit CVE-2025-0968?
Yes, unauthenticated attackers can exploit CVE-2025-0968 to access sensitive information.