CVE-2025-39589: WordPress Essential Addons for Elementor plugin <= 6.1.9 - Sensitive Data Exposure Vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Retrieve Embedded Sensitive Data.This issue affects Essential Addons for Elementor: from n/a through <= 6.1.9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39589?
CVE-2025-39589 has been classified as a medium severity vulnerability due to its potential for exposing sensitive system information.
How do I fix CVE-2025-39589?
To mitigate CVE-2025-39589, update the Essential Addons for Elementor plugin to version 6.2.0 or later.
What types of sensitive data can be exposed by CVE-2025-39589?
CVE-2025-39589 allows unauthorized access to embedded sensitive data within the Essential Addons for Elementor plugin.
Which versions of Essential Addons for Elementor are affected by CVE-2025-39589?
CVE-2025-39589 affects all versions of Essential Addons for Elementor from n/a through 6.1.9.
Is it safe to continue using Essential Addons for Elementor with CVE-2025-39589 present?
It is not safe to use Essential Addons for Elementor versions affected by CVE-2025-39589 without applying the necessary updates.