The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.18 in widgets/bwdeb-content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
CVE ID: CVE-2024-12532
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
Vendor: bestwpdeveloper
Product: BWD Elementor Addons (2500+ presets, Meet The Team, Lottie, Lord Icon, Masking, Woocommerce, Theme Builder, Products, Blogs, CV, Contact Form 7 Styler, Header, Slider, Hero Section)
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 16.22% (scored less or equal to compared to others)
EPSS Date: 2025-02-05 (when was this score calculated)