CVE-2024-3733 Overview
CVE-2024-3733 affects the Essential Addons for Elementor plugin for WordPress, a widely deployed suite of Elementor templates, widgets, and WooCommerce builders developed by wpdeveloper. The plugin exposes private and draft posts through three AJAX handlers: ajax_load_more(), eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery(). Unauthenticated attackers can query these endpoints and retrieve content that site administrators intended to keep hidden from public view. The flaw affects all plugin versions up to and including 5.9.15 and is categorized under [CWE-200] (Exposure of Sensitive Information) and [CWE-922] (Insecure Storage of Sensitive Information).
Critical Impact
Unauthenticated attackers can extract private and draft WordPress posts, exposing unpublished content, internal editorial workflows, and potentially confidential business information.
Affected Products
- Essential Addons for Elementor (Lite) versions up to and including 5.9.15
- WordPress installations running the wpdeveloper plugin with vulnerable AJAX handlers enabled
- Sites using the plugin's product gallery or load-more pagination widgets
Discovery Timeline
- 2024-04-25 - CVE-2024-3733 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-3733
Vulnerability Analysis
The vulnerability resides in three AJAX request handlers exposed by the Essential Addons for Elementor plugin. These handlers accept post-query parameters from client requests and pass them to WordPress query functions without enforcing post-status restrictions or verifying the requester's capability to view non-public content. As a result, an unauthenticated HTTP client can craft AJAX requests that return posts marked as private or draft.
The issue is an information exposure flaw rather than a code execution or data modification issue. Confidentiality is impacted while integrity and availability are not. The affected functions are used by widely deployed widgets, which increases the exposed attack surface for any WordPress site running the plugin.
Root Cause
The handlers ajax_load_more(), eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() accept user-controlled query arguments and pass them to WordPress post-fetch routines without sanitizing or restricting the post_status argument. The plugin also fails to check whether the current user has the read_private_posts capability before returning results. This combination allows unauthenticated requesters to enumerate content in non-public post states.
Attack Vector
Exploitation requires only network access to the WordPress site's admin-ajax.php endpoint. No authentication, user interaction, or elevated privileges are needed. An attacker sends a crafted POST request to the AJAX endpoint, supplying parameters that request posts with private or draft status. The vulnerable handler returns the post payload, including title and body content, in the response. See the Wordfence Vulnerability Report for additional technical context.
Detection Methods for CVE-2024-3733
Indicators of Compromise
- Repeated unauthenticated POST requests to /wp-admin/admin-ajax.php with action parameters load_more, eael_woo_pagination_product_ajax, or ajax_eael_product_gallery.
- Requests containing post_status values of private or draft in AJAX parameters.
- Anomalous volumes of AJAX traffic from a single IP or user agent targeting the Essential Addons endpoints.
Detection Strategies
- Inspect web server access logs for AJAX calls to the three vulnerable actions originating from unauthenticated sessions.
- Correlate AJAX request patterns with response sizes to identify bulk enumeration of post content.
- Deploy Web Application Firewall (WAF) rules that flag post_status=private or post_status=draft parameters in unauthenticated requests.
Monitoring Recommendations
- Alert on plugin version drift by tracking installed versions of essential-addons-for-elementor-lite across managed WordPress sites.
- Monitor outbound content in AJAX responses for post identifiers that map to unpublished content.
- Baseline normal AJAX request rates for the affected actions and alert on deviations.
How to Mitigate CVE-2024-3733
Immediate Actions Required
- Upgrade Essential Addons for Elementor to version 5.9.16 or later on all WordPress installations.
- Audit existing private and draft posts to determine whether unpublished content may have been exposed.
- Review web server logs for prior exploitation attempts targeting the vulnerable AJAX actions.
Patch Information
The vendor addressed the issue in version 5.9.16 by adding post-status restrictions to the affected handlers. The fix is visible in the WordPress Plugin Code Update changeset for Ajax_Handler.php.
Workarounds
- Temporarily deactivate the Essential Addons for Elementor plugin until the update is applied.
- Block unauthenticated requests to admin-ajax.php that include the vulnerable action parameters at the WAF layer.
- Restrict access to admin-ajax.php by IP allowlist where feasible for administrative sites.
# Configuration example: WP-CLI update to patched version
wp plugin update essential-addons-for-elementor-lite --version=5.9.16
wp plugin list --name=essential-addons-for-elementor-lite --fields=name,status,version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
