The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
Metrics
Affected Vendors & Products
References
History
Mon, 20 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Mon, 20 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators). | |
| Title | Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-20T13:09:48.210Z
Reserved: 2026-05-18T10:49:15.314Z
Link: CVE-2026-8825
Updated: 2026-07-20T13:09:37.363Z
No data.
No data.
OpenCVE Enrichment
No data.