Description
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without verifying edit capabilities. This makes it possible for authenticated attackers, with contributor-level access and above, to read private or draft Elementor template content via the 'template_id' supplied to the 'get_template_data' action of the 'elementor_ajax' endpoint.
Published: 2026-03-26
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Exposure
Action: Apply Patch
AI Analysis

Impact

The Elementor plugin in WordPress suffers from a permission check flaw that permits unauthorised reading of unpublished templates. The logic error in the is_allowed_to_read_template() function fails to verify that a user has edit rights before allowing visibility of draft or private templates. As a result, an attacker who is logged in with Contributor level or higher can retrieve the full contents of a template by supplying its template_id to the get_template_data action on the elementor_ajax endpoint. This yields confidential design information that should only be visible to template owners or administrators.

Affected Systems

WordPress installations running Elementor Website Builder version 3.35.7 or earlier are vulnerable. The flaw is present in all releases up to and including 3.35.7 and is not identified in later releases by the vendor. Site administrators should verify that the plugin is not at a vulnerable version.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, implying that large‑scale exploitation has not been observed. Attackers require only authenticated access with Contributor or higher rights, meaning anyone who can log into the site can try to leverage the flaw by submitting a template_id to the elementor_ajax endpoint. The impact is limited to the disclosure of template data and does not involve remote code execution or website takeover, but the availability of design assets may aid further attacks or intellectual property theft.

Generated by OpenCVE AI on March 26, 2026 at 07:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Elementor Website Builder to the most recent stable release available.
  • Verify that the plugin version is above 3.35.7 before applying the update.
  • Consider temporarily restricting Contributor roles or removing edit permissions on critical content while an update is applied.

Generated by OpenCVE AI on March 26, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Elemntor
Elemntor elementor Website Builder – More Than Just A Page Builder
Wordpress
Wordpress wordpress
Vendors & Products Elemntor
Elemntor elementor Website Builder – More Than Just A Page Builder
Wordpress
Wordpress wordpress

Thu, 26 Mar 2026 06:00:00 +0000

Type Values Removed Values Added
Description The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without verifying edit capabilities. This makes it possible for authenticated attackers, with contributor-level access and above, to read private or draft Elementor template content via the 'template_id' supplied to the 'get_template_data' action of the 'elementor_ajax' endpoint.
Title Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Elemntor Elementor Website Builder – More Than Just A Page Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:12:59.673Z

Reserved: 2026-01-19T16:01:46.785Z

Link: CVE-2026-1206

cve-icon Vulnrichment

Updated: 2026-03-26T17:48:03.395Z

cve-icon NVD

Status : Deferred

Published: 2026-03-26T06:16:09.267

Modified: 2026-04-24T16:35:20.070

Link: CVE-2026-1206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-26T12:08:29Z

Weaknesses