CVE-2026-32445: WordPress Elementor Website Builder plugin <= 3.35.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32445?
CVE-2026-32445 is categorized as a broken access control vulnerability with potential for significant security risks.
How do I fix CVE-2026-32445?
To fix CVE-2026-32445, update the Elementor Website Builder plugin to a version later than 3.35.5.
What types of attacks can CVE-2026-32445 facilitate?
CVE-2026-32445 can facilitate unauthorized access and manipulation of website content due to misconfigured access controls.
Who is affected by CVE-2026-32445?
CVE-2026-32445 affects users of the Elementor Website Builder plugin version 3.35.5 and earlier.
Is CVE-2026-32445 exploitable without authentication?
Yes, CVE-2026-32445 may be exploitable without proper authentication due to missing authorization checks.