MEDIUM (6.9)
    Plugin

    Elementor Website Builder Unauthorized Template Access Vulnerability

    Published Date: 3/26/2026
    CVE ID: CVE-2026-1206

    Summary

    A vulnerability in the Elementor Website Builder plugin for WordPress allows authenticated users with contributor-level access and above to access private or draft templates. The incorrect authorization check is present in versions up to 3.35.7.

    Vulnerability Details

    This vulnerability arises from a logic flaw in the 'is_allowed_to_read_template()' function within the Elementor Website Builder plugin for WordPress. Specifically, this flaw allows templates that are non-published and should be restricted to authorized users to become accessible to authenticated users with at least contributor-level rights. The flaw is exploited by supplying a 'template_id' to the 'get_template_data' action through the 'elementor_ajax' endpoint, thereby bypassing appropriate permission checks and gaining access to sensitive template content. This can lead to exposure of unapproved design data or proprietary information that might have been only meant for higher privilege levels. The real concern is that although these users cannot modify the template, the exposure of private information can be leveraged in other security breaches or information leaks. The vulnerability impacts versions of the plugin up to and including 3.35.7, and it necessitates action to prevent unauthorized data exposure.

    Recommendations

    To mitigate this vulnerability, first ensure to engage only trusted users at the contributor access level and limit their roles as needed. It is advisable to conduct a review of roles and capabilities attached to various user levels. Regularly audit permissions and access logs to monitor for suspicious or unauthorized access attempts to private template data.

    Available Fixes

    Last Updated: 3/28/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More