Skip to main content

Elementor Website Builder REST API Authorization Bypass Exposes Private Posts and Draft Content (CVE-2026-8825)

Scope: Elementor Website Builder Plugin Versions Prior to 4.1.4

Severity: High

An improper authorization check in Elementor Website Builder's REST API allows authenticated attackers with contributor-level access to query a vulnerable endpoint and retrieve the full title, body, and metadata of private posts, private pages, and drafts authored by other users including administrators, without any permission to access that content. Because contributor accounts are routinely granted to external content writers, freelancers, and lower-trust users on WordPress sites, this flaw exposes confidential internal content, unpublished announcements, draft policies, and any sensitive information stored in private posts to a broad class of potential attackers. Organizations must update Elementor Website Builder to version 4.1.4 immediately, audit contributor-level accounts and remove any that do not need active access, and review private and draft post content for any sensitive material that may have been exposed.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.