What is CVE-2026-13345?
This CVE is identified in the Essential Addons for Elementor WordPress plugin. Versions before 6.6.10 lack authorization, status, and visibility checks in the WooCommerce product comparison feature, allowing unauthenticated users to disclose title, price, and SKU of draft, pending, and private products. Updating the plugin to at least version 6.6.10 is recommended.
Azərbaycanca: Bu CVE "Essential Addons for Elementor" WordPress plaginində müəyyən edilib. 6.6.10 versiyasından əvvəlki versiyalarda WooCommerce məhsul müqayisə funksiyasında avtorizasiya çatışmazlığı səbəbindən autentifikasiya olunmamış istifadəçilər qaralama, gözləmədə olan və özəl məhsulların adı, qiyməti və SKU kimi məlumatlarını əldə edə bilər. Plagini ən azı 6.6.10 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the "Essential Addons for Elementor" plugin are vulnerable to CVE-2026-13345?
All versions prior to 6.6.10 are affected by this authorization bypass.
What type of product information can an unauthenticated user access through this vulnerability?
They can disclose the title, price, and SKU of draft, pending, and private WooCommerce products.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.