Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
Vulnerability Description
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Elementor Website Builder 信息泄露漏洞
Vulnerability Description
elemntor Elementor Website Builder – more than just a page builder是elemntor的CMS插件。 Elementor Website Builder 4.1.4之前版本存在信息泄露漏洞,该漏洞源于未正确检查用户权限,允许拥有贡献者级别及以上访问权限的认证用户检索其他用户(包括管理员)创建的私密文章、私密页面和草稿的标题、正文和元数据。
CVSS Information
N/A
Vulnerability Type
N/A