Back to overview

CVE-2026-8825

MEDIUM Exploitation: PoC
4.9
CVSS 3.1
Description
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

Metadata

CVE ID
CVE-2026-8825
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-18 10:49 UTC
Published
2026-07-20 06:00 UTC
Last updated
2026-07-20 13:09 UTC
Primary CWE
CWE-200
CWE-200 Exposure of Sensitive Information to an Unauthorized…
Vendor / Product
Unknown / Elementor Website Builder
Sources
cve.org  ·  NVD

Severity & Metrics

4.9 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown Elementor Website Builder 0 < 4.1.4
Weakness (CWE)
CWESourceDescription
cna CWE-200 Information Exposure
CWE-200 adp CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (1)
ScoreSeverityVersionSourceVector
4.9 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Back to overview