The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft, pending, or private status, which should normally be restricted.
We have discovered 88,870 live websites that are affected by CVE-2026-1004.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 88,870 live websites (32% of Essential Addons for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 146 versions ( 85% of all versions) |
| 20,999 websites | |
| 7,364 websites | |
| 5,003 websites | |
| 4,976 websites | |
| 3,589 websites | |
| 3,457 websites | |
| 3,300 websites | |
| 3,292 websites | |
| 3,204 websites | |
| 2,674 websites |
| .com | 34,749 websites |
| .com.br | 4,522 websites |
| .org | 3,976 websites |
| .de | 3,811 websites |
| .ru | 2,805 websites |
| .it | 2,387 websites |
| .fr | 2,082 websites |
| .pl | 2,003 websites |
| .co.uk | 1,788 websites |
| .net | 1,538 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | *,*** | ||
| ****************.nl | *,*** | ||
| ******************.de | **,*** | ||
| *******.co | **,*** | ||
| ******.com | **,*** | ||
| **********.com | **,*** | ||
| ******.com | **,*** | ||
| *******************.nl | **,*** | ||
| *******.com | **,*** | ||
| *******.com | **,*** |
FAQ