CVE-2026-8825

Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).


We have discovered 2,475,723 live websites that are affected by CVE-2026-8825.

Run a Free Instant Scan




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains2,475,723 live websites (93% of Elementor install base)
Vulnerable Versions
  • from 0 through 4.1.4
Vulnerable Versions Count341 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jul 20, 2026
  • Updated - Jul 20, 2026

Credits

  • Sarthak Saxena (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-8825
United States679,193 websites



Germany253,924 websites
France138,526 websites
GB103,790 websites
Brazil102,048 websites
Italy97,330 websites
Spain84,317 websites
Netherlands81,079 websites
Poland60,465 websites
India50,470 websites

Website Distribution by TLD

Number of websites using CVE-2026-8825
.com1,030,619 websites
.de149,276 websites
.org100,166 websites
.com.br94,872 websites
.nl72,924 websites
.it71,047 websites
.fr62,661 websites
.co.uk59,007 websites
.net49,518 websites
.pl46,146 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-8825

Top websites that are affected by CVE-2026-8825. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.io France***
**************.de Germany***
**********.com United States***
************.org United States***
**********.de Germany*,***
**************.org United States*,***
**********.com United States*,***
****.chat United States*,***
**********.de Germany*,***
******.io United States*,***
See full domain list

FAQ

CVE-2026-8825 is Exposure of Sensitive Information to an Unauthorized Actor in Elementor
A total of 2,475,723 websites have been identified as vulnerable to CVE-2026-8825, based on global website indexing conducted by WebTechSurvey.
The Elementor is affected by the CVE-2026-8825 vulnerability.
Elementor versions up to 4.1.4 are vulnerable to CVE-2026-8825.
CVE-2026-8825 is resolved in version 4.1.4 of Elementor.