Executive brief
A vulnerability in a popular WordPress plugin used for website design and e-commerce allows users with basic contributor access to view private or draft content. This could lead to the exposure of sensitive business information, unpublished product details, or internal templates that were intended to remain hidden from the public. The issue affects the 'Tabs' and 'Off Canvas' components of the plugin.
Technical details
The vulnerability is classified as a missing authorization check (CWE-862) within the render() method of the Envo Tabs and Off Canvas widgets. The plugin passes a user-controlled template or post ID directly to Elementor's get_builder_content_for_display() function without verifying the post's status (e.g., private, draft) or the requester's permissions. An authenticated attacker with Author-level privileges can exploit this by modifying widget JSON via the Elementor REST API to reference a private post ID. This causes the private content to be rendered and disclosed to anonymous visitors on a public-facing page. The issue is fixed in versions following 1.4.26.
Affected products
- EnvoThemes Envo's Templates & Widgets for Elementor and WooCommerce up to, and including, 1.4.26
Timeline
- 2026-07-02: disclosed: CVE-2026-11600 published by Wordfence/NVD
References
- https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.25/modules/off-canvas/widgets/off-canvas.php
- https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.25/modules/tabs/widgets/tabs.php
- https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.25/modules/tabs/widgets/tabs.php
- https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.26/modules/off-canvas/widgets/off-canvas.php
- https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.26/modules/tabs/widgets/tabs.php
- https://plugins.trac.wordpress.org/browser/envo-elementor-for-woocommerce/tags/1.4.26/modules/tabs/widgets/tabs.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3578489%40envo-elementor-for-woocommerce&new=3578489%40envo-elementor-for-woocommerce&sfp_email=&sfph_mail=