cleantalk
Vulnerabilities and Security Researches

Elementor Custom Skin, CVE-2026-14229

CVE, Research URL

CVE-2026-14229

Application

Elementor Custom Skin

Published on
Aug 15, 2026
Research Description
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier.
Affected versions
max 4.3.8.
Status
vulnerable