Description
The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user-controlled template/post ID directly to Elementor's get_builder_content_for_display() without verifying the referenced post's status (published/private/draft) or the visitor's authorization to view it. This makes it possible for authenticated attackers, with Author-level access and above, to disclose the contents of private Elementor-driven pages and templates to anonymous visitors by configuring an Envo Tabs widget on a public post to reference the private content's ID (which can be supplied by editing the underlying Elementor widget JSON via the Elementor editor REST API).
Published: 2026-07-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress contains a missing authorization check in the Envo Tabs and Off‑Canvas widgets. The widget’s render() method passes a user‑supplied template or page ID directly to Elementor’s get_builder_content_for_display() without verifying whether the referenced post is published, private, or draft, or whether the viewer is entitled to view it. This flaw, classified as CWE‑862, allows an authenticated Author‑level user or any higher‑privileged user to embed the ID of a private or draft Elementor page in a public post. When that post is accessed by anonymous visitors, the private content is effectively leaking confidential Elementor‑driven pages to unauthenticated users.

Affected Systems

WordPress installations that have the Envo's Templates & Widgets for Elementor and WooCommerce plugin installed, using any version up to and including 1.4.26. Sites with accounts that grant Author or higher access and that enable editing of widget JSON via the Elementor REST API are vulnerable, because those users can supply the private content ID to the affected widget.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability that this vulnerability will be widely exploited in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate user with Author‑level (or can modify widget JSON, after which the compromised widget causes persistent disclosure of private Elementor content to anyone who visits the public post.

Generated by OpenCVE AI on July 21, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Envo's Templates & Widgets for Elementor and WooCommerce to the latest release that adds the missing authorization check.
  • Inspect all public posts that use Envo Tabs or Off‑Canvas widgets and remove or replace any instances that reference private or draft Elementor templates.
  • Restrict or disable the Elementor REST API endpoints that allow JSON editing for users with Author or higher capabilities, or enforce role‑based filtering so only administrators can modify widget configurations.

Generated by OpenCVE AI on July 21, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user-controlled template/post ID directly to Elementor's get_builder_content_for_display() without verifying the referenced post's status (published/private/draft) or the visitor's authorization to view it. This makes it possible for authenticated attackers, with Author-level access and above, to disclose the contents of private Elementor-driven pages and templates to anonymous visitors by configuring an Envo Tabs widget on a public post to reference the private content's ID (which can be supplied by editing the underlying Elementor widget JSON via the Elementor editor REST API).
Title Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-02T15:54:20.863Z

Reserved: 2026-06-08T14:54:04.597Z

Link: CVE-2026-11600

cve-icon Vulnrichment

Updated: 2026-07-02T14:04:50.411Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:30:03Z

Weaknesses