Premium Addons for Elementor Unauthorized Data Access Vulnerability (CVE-2025-14155) — Medium Severity

Understanding the Unauthorized Access Vulnerability in Premium Addons for Elementor

A notable security flaw has been identified in the “Premium Addons for Elementor – Powerful Elementor Templates & Widgets” plugin for WordPress. This vulnerability, tracked as CVE-2025-14155, could allow unauthorized individuals to access sensitive content on your website. For any website owner using this popular Elementor addon, understanding this risk and applying the necessary fix is crucial.

At its core, this vulnerability stems from a missing security check within a specific function of the plugin. This oversight means that even visitors who are not logged in or do not have proper permissions could potentially view content from private, draft, or pending templates on your WordPress site. This could expose information that was never intended for public eyes, posing a significant privacy and security risk.

CVE Details

Product: Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress

CVE ID: CVE-2025-14155

Published: December 23, 2025

Severity: Medium

Status: Analyzed

Affected Products

The vulnerability impacts all versions of the “Premium Addons for Elementor” plugin for WordPress up to, and including, version 4.11.53. If you are running any version within this range, your website may be at risk.

Current Status

The vulnerability has been thoroughly analyzed, meaning its nature and potential impact are well understood. A fix has been released by the plugin developers.

Severity Level

CVE-2025-14155 is rated as Medium severity. This indicates that while the vulnerability could lead to information disclosure, it might require specific conditions or user interaction (though in this case, unauthenticated access is possible) and does not typically allow for full system compromise or remote code execution. However, exposing draft or private content still carries significant risks for website integrity and reputation, making prompt action highly advisable.

Possible Solutions

The good news is that a patch is available to address this vulnerability. Users of the Premium Addons for Elementor plugin should update to version 4.11.54 or higher immediately. This update introduces the necessary capability checks to the 'get_template_content' function, preventing unauthorized access to your private, draft, and pending templates.

Always ensure your WordPress core, themes, and all plugins are kept up-to-date to protect your site from known vulnerabilities.

References

https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.53/includes/addons-integration.php#L1624

https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.11.53/includes/addons-integration.php#L90

https://plugins.trac.wordpress.org/changeset/3416254/

https://www.wordfence.com/threat-intel/vulnerabilities/id/135c33bb-5ec2-4697-9340-1d2651ff3a0b?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.