CVE-2026-8825: Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8825?
CVE-2026-8825 has a risk score of 48, indicating a moderate severity level.
How do I fix CVE-2026-8825?
To fix CVE-2026-8825, update the Elementor Website Builder plugin to version 4.1.4 or later.
What type of vulnerability is CVE-2026-8825?
CVE-2026-8825 is classified as an Information Leak vulnerability affecting user permissions.
What is affected by CVE-2026-8825?
CVE-2026-8825 affects the Elementor Website Builder plugin for WordPress prior to version 4.1.4.
Who is at risk from CVE-2026-8825?
Authenticated users with Contributor-level access and above are at risk of exploiting CVE-2026-8825 to access sensitive information.