CVE-2026-11600
Last modified
CVE-2026-11600 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user-controlled template/post ID directly to Elementor's get_builder_content_for_display() without verifying the referenced post's status (published/private/draft) or the visitor's authorization to view it. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a user-controlled template/post ID directly to Elementor's get_builder_content_for_display() without verifying the referenced post's status (published/private/draft) or the visitor's authorization to view it. This makes it possible for authenticated attackers, with Author-level access and above, to disclose the contents of private Elementor-driven pages and templates to anonymous visitors by configuring an Envo Tabs widget on a public post to reference the private content's ID (which can be supplied by editing the underlying Elementor widget JSON via the Elementor editor REST API).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| envothemes | Envo's Templates & Widgets for Elementor and WooCommerce | <= 1.4.26 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-11600?
How severe is CVE-2026-11600?
How do I fix CVE-2026-11600?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11594IBM WebSphere Application Server 9.0, and 8.5 is affected by…6.1
- CVE-2026-11595IBM WebSphere Application Server 9.0, and 8.5 could allow a …7.5
- CVE-2026-11596In ScreenConnect™ versions prior to 26.2, input validation w…4.7
- CVE-2026-11597The Surbma | Infusionsoft Shortcode plugin for WordPress is …6.4
- CVE-2026-11598The Shortcodify plugin for WordPress is vulnerable to Stored…5
- CVE-2026-1160A security vulnerability has been detected in PHPGurukul Dir…9.8
- CVE-2026-11603The Product Filter Widget for Elementor plugin for WordPress…6.1
- CVE-2026-11604An incorrect buffer size calculation in the epoch key genera…6.5
- CVE-2026-11605The issue is a resource exhaustion vulnerability associated …7.5
- CVE-2026-11607Backend users with access to the Form Framework were able to…7.6
- CVE-2026-11608The WP Customer Reviews plugin for WordPress is vulnerable t…6.1
- CVE-2026-11609Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-11600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
