Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-11600— Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting

CVSS 4.3 · Medium EPSS 0.24% · P15

Affected Version Matrix 1

VendorProductVersion RangeStatus
envothemesEnvo's Templates & Widgets for Elementor and WooCommerce≤ 1.4.26affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-11600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting
Source: CVE Program / CVE List V5
Vulnerability Description
The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user-controlled template/post ID directly to Elementor's get_builder_content_for_display() without verifying the referenced post's status (published/private/draft) or the visitor's authorization to view it. This makes it possible for authenticated attackers, with Author-level access and above, to disclose the contents of private Elementor-driven pages and templates to anonymous visitors by configuring an Envo Tabs widget on a public post to reference the private content's ID (which can be supplied by editing the underlying Elementor widget JSON via the Elementor editor REST API).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Envo's Templates & Widgets for Elementor and WooCommerce 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress Envo's Templates & Widgets for Elementor and WooCommerce是WordPress基金会的一款集成模板与小工具的网页设计组件包。 WordPress Envo's Templates & Widgets for Elementor and WooCommerce 1.4.26及之前版本存在授权问题漏洞,该漏洞源于对Envo Tabs widget的模板渲染缺少授权检查,可能导致经过身份验证的攻击者(具有作者级及以上权限)向匿名访问者泄露
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
envothemesEnvo's Templates & Widgets for Elementor and WooCommerce 0 ~ 1.4.26 -

II. Public POCs for CVE-2026-11600

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11600

登录查看更多情报信息。

Patches & Fixes for CVE-2026-11600 (1)

News Coverage for CVE-2026-11600 (1)

Other References for CVE-2026-11600 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-11600

No comments yet


Leave a comment