PT-2026-61536 · WordPress · Elementor Website Builder

·

CVE-2026-8825

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elementor Website Builder WordPress plugin versions prior to 4.1.4
Description An issue exists where user permissions are not properly verified before returning post data through a REST endpoint. This allows authenticated users with Contributor-level access or higher to retrieve the title, body, and metadata of private posts, private pages, and drafts created by other users, including administrators.
Recommendations Update the Elementor Website Builder WordPress plugin to version 4.1.4 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8825

Affected Products

Elementor Website Builder