CVE-2026-1004: Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure
The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eaelproductquickviewpopup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1004?
The severity of CVE-2026-1004 is considered high due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2026-1004?
To fix CVE-2026-1004, update the Essential Addons for Elementor plugin to the latest version beyond 6.5.5.
Who is affected by CVE-2026-1004?
All users of the Essential Addons for Elementor plugin for WordPress version 6.5.5 and earlier are affected by CVE-2026-1004.
What type of vulnerability is CVE-2026-1004?
CVE-2026-1004 is classified as a Missing Authorization vulnerability that leads to Sensitive Information Exposure.
What can an attacker do with CVE-2026-1004?
An attacker can potentially exploit CVE-2026-1004 to access sensitive information without authentication.