Junglewise Threat Intelligence

CVE-2026-57619: Elementor Website Builder sensitive data exposure in WordPress plugin

CVE-2026-57619 · Severity: medium · CVSS 6.5 · Published 2026-06-25

Technologies: Elementor Website Builder. Vendors: Elementor.

Executive brief

Elementor Website Builder is a popular WordPress plugin used to design and build websites. A security vulnerability in versions 4.1.3 and earlier allows users with 'Contributor' level access to view sensitive information that should normally be restricted. This could lead to the exposure of internal site data, potentially helping an attacker plan further unauthorized actions against the website.

Technical details

A sensitive data exposure vulnerability exists in the Elementor Website Builder plugin for WordPress due to missing authorization (CWE-862). An attacker with 'Contributor' level privileges can exploit this flaw to access information that is intended to be restricted from their role. The vulnerability is reachable over the network without user interaction, provided the attacker has a valid low-level account. The issue is resolved in version 4.1.4.

Affected products

  • Elementor Elementor Website Builder <= 4.1.3

Timeline

  • 2026-01-08: other: Reported by Steven Julian
  • 2026-06-25: advisory: Published by Patchstack and NVD
  • 2026-06-25: patched: Version 4.1.4 released to address the issue

References

Related threats