Beschreibung
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic error in the is_allowed_to_read_template() function permission check that treats non-published templates as readable without verifying edit capabilities. This makes it possible for authenticated attackers, with contributor-level access and above, to read private or draft Elementor template content via the -template_id- supplied to the -get_template_data- action of the -elementor_ajax- endpoint.
CVSS 4.3EPSS 0.25%Risiko 0.44
Quelle öffnen- Veröffentlicht
- 2026-03-26 06:16:09
- Betroffene Versionen
- <=3.35.7
- Typ
- Package
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N