CVE-2025-14155

Source
https://cve.org/CVERecord?id=CVE-2025-14155
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14155.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14155
Published
2025-12-23T10:15:43.297Z
Modified
2026-03-12T17:36:44.979287Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gettemplatecontent' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "4.11.54"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14155.json"