Review
Elementor
CVE published 2026-07-20
CVE-2026-8825
This CVE debrief covers CVE-2026-8825, a vulnerability in the Elementor Website Builder WordPress plugin. The issue allows authenticated users with Contributor-level access and above to retrieve private post, page, and draft data through REST endpoints. This exposure affects users who haven't updated to version 4.1.4 or later. The vulnerability is considered medium severity, requiring immediate attention [truncated]