WordPress · Elementor Website Builder · CVE-2026-8825
**Name of the Vulnerable Software and Affected Versions**
Elementor Website Builder WordPress plugin versions prior to 4.1.4
**Description**
An issue exists where user permissions are not properly verified before returning post data through a REST endpoint. This allows authenticated users with Contributor-level access or higher to retrieve the title, body, and metadata of private posts, private pages, and drafts created by other users, including administrators.
**Recommendations**
Update the Elementor Website Builder WordPress plugin to version 4.1.4 or later.