Impact
The Elementor WordPress plugin before version 4.1.4 does not correctly verify user permissions on one of its REST API endpoints. As a result, any authenticated user with Contributor level or higher can retrieve the title, body, and metadata of private posts, private pages, and drafts authored by other users, including administrators. This flaw, categorized as CWE‑200: Information Exposure from Input or Output, allows an attacker to expose confidential content that should otherwise remain hidden from non‑owners.
Affected Systems
The issue impacts all sites running Elementor Website Builder versions earlier than 4.1.4. Any WordPress installation that has the plugin installed and has user accounts with Contributor or higher roles is vulnerable regardless of hosting environment.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity. The EPSS score of less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would issue a direct HTTP GET request to the exposed REST endpoint after authenticating with at least Contributor privileges. The main consequence is the compromise of confidentiality for private posts and drafts.
OpenCVE Enrichment