Impact
Live Copy Paste for Elementor versions 1.5.3 and earlier contain a broken access control flaw (CWE‑862). The vulnerability allows an attacker to bypass normal permission checks when using the plugin’s copy‑paste feature.
Affected Systems
The affected product is the BDThemes Live Copy Paste for Elementor WordPress plugin, version 1.5.3 and all earlier releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity issue. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attack vectors are likely through the plugin’s user interface, possibly requiring authenticated access or content editor privileges, but the exact conditions are not detailed. While the likelihood of exploitation is unclear without EPSS data, the ability to bypass access control warrants prompt attention.
OpenCVE Enrichment