Understanding the Unauthorized Access Vulnerability in Premium Addons for Elementor
A notable security flaw has been identified in the “Premium Addons for Elementor – Powerful Elementor Templates & Widgets” plugin for WordPress. This vulnerability, tracked as CVE-2025-14155, could allow unauthorized individuals to access sensitive content on your website. For any website owner using this popular Elementor addon, understanding this risk and applying the necessary fix is crucial.
At its core, this vulnerability stems from a missing security check within a specific function of the plugin. This oversight means that even visitors who are not logged in or do not have proper permissions could potentially view content from private, draft, or pending templates on your WordPress site. This could expose information that was never intended for public eyes, posing a significant privacy and security risk.
CVE Details
Product: Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress
CVE ID: CVE-2025-14155
Published: December 23, 2025
Severity: Medium
Status: Analyzed
Affected Products
The vulnerability impacts all versions of the “Premium Addons for Elementor” plugin for WordPress up to, and including, version 4.11.53. If you are running any version within this range, your website may be at risk.
Current Status
The vulnerability has been thoroughly analyzed, meaning its nature and potential impact are well understood. A fix has been released by the plugin developers.
Severity Level
CVE-2025-14155 is rated as Medium severity. This indicates that while the vulnerability could lead to information disclosure, it might require specific conditions or user interaction (though in this case, unauthenticated access is possible) and does not typically allow for full system compromise or remote code execution. However, exposing draft or private content still carries significant risks for website integrity and reputation, making prompt action highly advisable.
Possible Solutions
The good news is that a patch is available to address this vulnerability. Users of the Premium Addons for Elementor plugin should update to version 4.11.54 or higher immediately. This update introduces the necessary capability checks to the 'get_template_content' function, preventing unauthorized access to your private, draft, and pending templates.
Always ensure your WordPress core, themes, and all plugins are kept up-to-date to protect your site from known vulnerabilities.
References
https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.53/includes/addons-integration.php#L1624
https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.53/includes/addons-integration.php#L90
https://plugins.trac.wordpress.org/changeset/3416254/
https://www.wordfence.com/threat-intel/vulnerabilities/id/135c33bb-5ec2-4697-9340-1d2651ff3a0b?source=cve


