Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam essential Addons For Elementor |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam essential Addons For Elementor |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view. | |
| Title | Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T17:12:56.492Z
Reserved: 2026-06-25T14:13:30.190Z
Link: CVE-2026-13345
Updated: 2026-07-30T17:12:41.419Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T13:30:04Z
-
CWE-639
Authorization Bypass Through User-Controlled Key