PT-2026-61536 · WordPress · Elementor Website Builder
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Elementor Website Builder WordPress plugin versions prior to 4.1.4
Description
An issue exists where user permissions are not properly verified before returning post data through a REST endpoint. This allows authenticated users with Contributor-level access or higher to retrieve the title, body, and metadata of private posts, private pages, and drafts created by other users, including administrators.
Recommendations
Update the Elementor Website Builder WordPress plugin to version 4.1.4 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elementor Website Builder