Description
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
Published: 2026-07-20
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Elementor WordPress plugin before version 4.1.4 does not correctly verify user permissions on one of its REST API endpoints. As a result, any authenticated user with Contributor level or higher can retrieve the title, body, and metadata of private posts, private pages, and drafts authored by other users, including administrators. This flaw, categorized as CWE‑200: Information Exposure from Input or Output, allows an attacker to expose confidential content that should otherwise remain hidden from non‑owners.

Affected Systems

The issue impacts all sites running Elementor Website Builder versions earlier than 4.1.4. Any WordPress installation that has the plugin installed and has user accounts with Contributor or higher roles is vulnerable regardless of hosting environment.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity. The EPSS score of less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would issue a direct HTTP GET request to the exposed REST endpoint after authenticating with at least Contributor privileges. The main consequence is the compromise of confidentiality for private posts and drafts.

Generated by OpenCVE AI on July 30, 2026 at 19:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Elementor plugin to version 4.1.4 or later
  • Immediately revoke Contributor roles or downgrade affected accounts until the update is applied
  • If an upgrade is not possible, block or restrict the vulnerable REST endpoint with a firewall or security plugin

Generated by OpenCVE AI on July 30, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Elementor
Elementor elementor Website Builder
Wordpress
Wordpress wordpress
Vendors & Products Elementor
Elementor elementor Website Builder
Wordpress
Wordpress wordpress

Mon, 20 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
Title Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
References

Subscriptions

Elementor Elementor Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-20T13:09:48.210Z

Reserved: 2026-05-18T10:49:15.314Z

Link: CVE-2026-8825

cve-icon Vulnrichment

Updated: 2026-07-20T13:09:37.363Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor