Elementor Website Builder: A security weakness
Elementor Website Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.1.4.
- Component
- Elementor Website Builder
- Plugin slug
elementor-website-builder- Affected
- < 4.1.4
- Safe version
4.1.4- Published
- Jul 20, 2026
This CVE was published Jul 20, 2026 and is one of 2 known issues for this plugin.
Patch or disable the affected component.
Update Elementor Website Builder to 4.1.4 or later, or disable and remove it until a fixed version is available.
Technical description
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N