CVE-2026-49782: WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Elementor Website Builder: from n/a through 4.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Elementor Website Builder Pluginto a version that resolves this vulnerability.Fixed in 4.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49782?
CVE-2026-49782 has a medium severity rating of 5.4.
How do I fix CVE-2026-49782?
To fix CVE-2026-49782, update the WordPress Elementor Website Builder Plugin to the latest version, at least 4.1.1.
What type of vulnerability is CVE-2026-49782?
CVE-2026-49782 is a Broken Access Control vulnerability allowing exploitation of incorrectly configured access controls.
Which versions of Elementor are affected by CVE-2026-49782?
CVE-2026-49782 affects Elementor Website Builder from version n/a through 4.1.0.
What can happen if CVE-2026-49782 is exploited?
Exploiting CVE-2026-49782 may lead to unauthorized access and manipulation of restricted areas of a website.