CVE-2026-28131 PUBLISHED

WordPress Elementor Addon Elements plugin <= 1.14.4 - Sensitive Data Exposure vulnerability

Assigner: Patchstack
Reserved: 25.02.2026 Published: 26.02.2026 Updated: 26.02.2026

Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4.

Product Status

Vendor WPVibes
Product Elementor Addon Elements
Versions Default: unaffected
  • affected from n/a to <= 1.14.4 (incl.)

Credits

  • Abu Hurayra | Patchstack Bug Bounty Program finder

References

Problem Types

  • Insertion of Sensitive Information Into Sent Data CWE

Impacts

  • Retrieve Embedded Sensitive Data