CVE-2026-8825 - Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
CVE ID :CVE-2026-8825
Published : July 20, 2026, 7:16 a.m. | 3 hours, 32 minutes ago
Description :The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 20, 2026, 7:16 a.m. | 3 hours, 32 minutes ago
Description :The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...