SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-8825

MEDIUM · CVSS 4.9 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Elementor Website Builder plugin for WordPress versions prior to 4.1.4 is vulnerable due to inadequate user permission checks in its REST endpoints, enabling authenticated users with Contributor-level access or higher to access private posts, pages, and drafts authored by others, including administrators. This could lead to unauthorized disclosure of sensitive content within the site. WordPress site administrators and security teams should prioritize this vulnerability to mitigate potential data leaks.

CVE
CVE-2026-8825
Severity
MEDIUM
CVSS
4.9
EPSS
0.23%
WordPress

Original NVD Description

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).