Junglewise Threat Intelligence

CVE-2026-49782: Elementor Website Builder missing authorization in access control

CVE-2026-49782 · Severity: medium · CVSS 5.4 · Published 2026-06-02

Technologies: Elementor Website Builder. Vendors: Elementor.

Executive brief

Elementor is a popular website building tool for WordPress. A security flaw in versions up to 4.1.0 allows users with low-level access (such as contributors) to perform actions they should not be authorized to do. This could lead to unauthorized changes to website content or settings, though the overall risk is considered moderate.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Elementor Website Builder plugin for WordPress in versions up to and including 4.1.0. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An attacker with 'Contributor' level privileges or higher can exploit this over the network without user interaction to perform unauthorized actions. The vulnerability is addressed in version 4.1.1.

Affected products

  • Elementor Elementor Website Builder up to 4.1.0

Timeline

  • 2025-11-30: other: Reported by researcher Bonds
  • 2026-06-02: advisory: Published by Patchstack and NVD
  • 2026-06-02: patched: Fixed in version 4.1.1

References

Related threats